new_player.exe

Plugin Update SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application new_player.exe by Plugin Update SL has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from kyle.mxp4122.com and multiple other hosts.
Publisher:
Plugin Update SL  (signed and verified)

Version:
1.0.0.1

MD5:
046297baeef477146c92f4d714a7544b

SHA-1:
03b5c414ade29d3c49ca83214e38eef9d06011c7

SHA-256:
4e61b766b6bc509e3d901a3e6f2ffa468a62ac488f29718c17a010cce3434eaf

Scanner detections:
20 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/21/2024 1:48:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.SoftPulse.2
840

AegisLab AV Signature
AdWare.MSIL.DomaIQ
2.1.4+

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/SoftPulse
2014.10.18

Avira AntiVirus
APPL/Softpulse.Gen8
7.11.179.100

avast!
Win32:SoftPulse-AH [PUP]
141003-0

AVG
Generic
2015.0.3318

Bitdefender
Gen:Variant.Application.Bundler.SoftPulse.2
1.0.20.1450

ESET NOD32
Win32/SoftPulse (variant)
8.10580

Fortinet FortiGate
W32/Buzus.UUTA!tr
10/17/2014

F-Prot
W32/A-a1299ecf
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Bundler
11.2014-17-10_6

G Data
Gen:Variant.Application.Bundler.SoftPulse
14.10.24

K7 AntiVirus
Unwanted-Program
13.184.13718

McAfee
Softpulse.b
5600.6974

MicroWorld eScan
Gen:Variant.Application.Bundler.SoftPulse.2
15.0.0.870

Reason Heuristics
PUP.PluginUpdateSL.K
14.10.17.15

Sophos
SoftPulse
4.98

Vba32 AntiVirus
BScope.Adware.Softpulse
3.12.26.3

VIPRE Antivirus
Threat.4783235
33706

File size:
1.4 MB (1,434,080 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
English

Common path:
C:\users\{user}\downloads\new_player.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/12/2014 1:00:00 AM

Valid to:
6/13/2015 12:59:59 AM

Subject:
CN=Plugin Update SL, O=Plugin Update SL, L=Guia De Isora, S=Tenerife, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1858913428C49A270BE00711E97381C6

File PE Metadata
Compilation timestamp:
9/26/2014 1:52:54 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:j8gP2Rq9XZbJNRg4pCz3qv4nR32WbRCbF9TgjwYhqmK1KvwVevm7IfT3GuRVO:jNOkNe4OvnLCJ9Tg09mXBFf7Gr

Entry address:
0x7DD0

Entry point:
E8, C8, 41, 00, 00, E9, 7F, FE, FF, FF, E9, 3E, 27, 00, 00, FF, 35, 94, 4E, 47, 00, FF, 15, A4, 70, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, 0A, 49, 00, 00, 59, 59, E9, 22, 49, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 62, 49, 00, 00, 59, 85, C0, 74, 11, FF, 75, 08, E8, C0, 2C, 00, 00, 59, 85, C0, 74, E6, 8B, E5, 5D, C3, 6A, 01, 8D, 45, FC, C7, 45, FC, EC, B8, 46, 00, 50, 8D, 4D, F0, E8, 27, 30, 00, 00, 68, FC, 1D, 47, 00, 8D, 45, F0, C7, 45, F0, E4, B8, 46, 00, 50, E8, 7C, 27, 00...
 
[+]

Entropy:
7.5323

Code size:
85.5 KB (87,552 bytes)

The file new_player.exe has been seen being distributed by the following 3 URLs.

Remove new_player.exe - Powered by Reason Core Security