media player.exe

MaRI MArA

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application media player.exe by MaRI MArA has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
KKOVS  (signed by MaRI MArA)

Product:
KKOVS

Version:
8617.15613.826.3780

MD5:
0f4e20743a674980017e3b7b69b3ba0d

SHA-1:
76db50585ee5fa19746ab3e1acbbcf759d0474e3

SHA-256:
b5b5ca3b09bd5f76b616fb9803cf0bca89e6a8ae305ecb4df72a63185de14897

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/21/2024 10:46:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.7.26.8

File size:
724.8 KB (742,192 bytes)

Product version:
8617.15613.826.3780

Copyright:
KKOVS

Trademarks:
KKOVS

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\media player.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/11/2015 12:00:00 PM

Valid to:
12/18/2015 12:59:59 PM

Subject:
CN=MaRI MArA, O=MaRI MArA, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5D3973BCF3BBD250BC14EB900D1D372D

File PE Metadata
Compilation timestamp:
12/6/2009 11:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:mh00l/8C3qo8D7mAAZrpbg+/pX8DxFHyTkbyQeEsgA2hetIZmDfc8vy4hS:mnECr8D7AgOKDxFBy1ehetIH86P

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9828

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove media player.exe - Powered by Reason Core Security