mkvplayer_setup.exe

Rspark LLC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application mkvplayer_setup.exe by Rspark has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Rspark LLC  (signed and verified)

MD5:
0c0b96d4facc2b4eb9d6a7ebfd6dd389

SHA-1:
443e69521c00bc52ab3f7f23b8920c47ffc7c9a7

SHA-256:
1ddf8b1724690b6aca401ee67f92d2c34dc4734175ecdff00b2dca363225cda2

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/27/2024 4:54:27 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.165.4

AVG
Generic
2015.0.3395

Dr.Web
Trojan.Packed.28387
9.0.1.0254

ESET NOD32
Win32/OutBrowse.AC
8.10193

herdProtect (fuzzy)
2014.9.11.6

Malwarebytes
PUP.Optional.OutBrowse
v2014.08.01.11

McAfee
Artemis!493C49A53713
5600.7051

nProtect
Trojan-Downloader/W32.Genome.567376
14.08.01.01

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Rspark.P
14.8.1.23

Sophos
Generic PUA HL
4.98

Trend Micro House Call
Suspicious_GEN.F47V0726
7.2.254

VIPRE Antivirus
OutBrowse
31854

File size:
554.1 KB (567,376 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/11/2014 7:00:00 PM

Valid to:
2/12/2015 6:59:59 PM

Subject:
CN=Rspark LLC, O=Rspark LLC, STREET="2929 1st ave #405", L=Seattle, S=Washington, PostalCode=98121, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E4DA7826149424E5DF9F3646FF2E80B9

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:0wjkdBNYp/g4zWMM1jOVrILdCIEoFroMx/xZCvikKWF4:0aoX1MSOVdCMMdTSKWG

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9761

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file mkvplayer_setup.exe has been seen being distributed by the following URL.

Remove mkvplayer_setup.exe - Powered by Reason Core Security