smplayer_14.3.0_setup.exe

Opensource

The application smplayer_14.3.0_setup.exe by Opensource has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from downloads.smplayer.info.
Publisher:
Opensource  (signed and verified)

MD5:
c338a883758119345f94b33e7fdba77e

SHA-1:
553384f371c43ff9503264310655c8a979157740

SHA-256:
0a5c03a990a08c8701f85d3d3d1010b1efbc8371bdbd866f8bbe47e5f36d8109

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 8:10:45 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Dr.Web
Trojan.MulDrop5.10078
9.0.1.05190

ESET NOD32
Win32/InstallCore.BY potentially unwanted application
7.0.302.0

F-Prot
W32/A-42c63c6c
v6.4.7.1.166

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14801

SUPERAntiSpyware
10444

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4837543
31208

File size:
703.2 KB (720,072 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\smplayer_14.3.0_setup.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
10/14/2013 2:06:56 PM

Valid to:
10/14/2014 2:06:56 PM

Subject:
E=ricardo@smplayerteam.com, CN="Open Source Developer, Ricardo Villalba", O=Opensource, C=ES

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
10EAA7D7B21F864E907092A072BF820A

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:TyMJfsGG1k38GshgatiD84QajhwqrVpA72ddUMSyZYL2hthoacNGv/E1:TyMJfsv1kMFhgx8gwqrjA72ddUEmLYj/

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file smplayer_14.3.0_setup.exe has been seen being distributed by the following URL.

Remove smplayer_14.3.0_setup.exe - Powered by Reason Core Security