uplayermediaplayer-setup.exe

Full Spectrum Interactive

The application uplayermediaplayer-setup.exe by Full Spectrum Interactive has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from s.m2pub.com and multiple other hosts.
Publisher:
Full Spectrum Interactive  (signed and verified)

MD5:
6a65557f174ee3fb772c7bf417cb4caf

SHA-1:
ced815d315e0df3b07ff6f82d007ee1499cbff83

SHA-256:
f2a731bd73f5e96dc254a0782a85323a044db73604cc82fc30596bb101d5f360

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 11:25:41 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/DownloadAdmin.AH.5
7.11.109.96

Dr.Web
Adware.DownloadAdmin.1
9.0.1.025

ESET NOD32
Win32/DownloadAdmin
8.9444

NANO AntiVirus
Trojan.Win32.Downware.crgjbr
0.28.0.57630

Reason Heuristics
PUP.Installer.FullSpectrumInteractive.Y
14.2.24.5

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14312

Sophos
Download Admin
4.97

Trend Micro House Call
TROJ_GEN.F47V0904
7.2.25

VIPRE Antivirus
DownloadAdmin
26632

File size:
576.7 KB (590,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayer\uplayermediaplayer-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/10/2012 8:00:00 PM

Valid to:
6/10/2014 7:59:59 PM

Subject:
CN=Full Spectrum Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Full Spectrum Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A1AEF489C94F2C514EA16B9BEBCDEFC

File PE Metadata
Compilation timestamp:
6/22/2012 2:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:TYQxt2ctKQEGvjITZD+jcEckHnyudpc5y/zDnYDBrfw8A9:TlxIQEMIT5dAzc5y/zUDBri

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9663

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file uplayermediaplayer-setup.exe has been seen being distributed by the following 50 URLs.

http://s.m2pub.com/event/click/0/OfJXUHZncoztimdFcUIZVshrm6nBjLC3w8G_CBVGe0a2nO9nhNwfGVcdWdxkPpKyQbh5VSFdzbg5uMsixvO5qA5W5Sm1xfjOu8jixJwe1lL7eqWt1_dPoWbDGVPjwGIjuy9GyEUKPY16dU7A-pwIlIypSM1mH1-Zbs731vw_F6J5Qx_OeC4x6A5vJxjIAAC70bOHZE8EPT7R3laq32nySjFJReN85xPohu2aveFfqhXA9sYxUoY2vwFUvgKlq9dCgjSZkCc09n-fDnV-LJlVtG-S01GnNWgupSsrikf9YWppw1vA6TNaKhy5TnPo17vGdq7F_Q/.../

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=UxMozsagCjvTl92_6_ILhVjtVJjO9Yq5t_lP0Zs9vYKN-_AfQ0UeqxI3hZoUT25D-ZRf6QTJG-97siTZRr007Yoy0_Ix6xgFe55YC7dQ966vDAY1l_OAJDSaw6U7Vuc95OfAgcrX6dJTtATRj_SaVs-O7BXUwo2Y6ii-hWmfFyCv-AtrhgijHcRs1OWMe2vt6tNN9H37v56OOJlDfLaGY7eAvxhhFCiWozjlrv8VGlEwN70ifnxEY-S-zeL0CYRvPYnriHVmzpSbnpZTDPYQWyEikRmDKAXZRcRzq3PYg0OG6R-ox8VGBQhMDE-4nZyxghBjppQCP6Kc98nPxA6js0Fu8BiGmP3Tfv5fRPWUvqbnQza2Pc8fLQ

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=dTcwBpb0di-OO1HJ_i5HfZBx9wAPit3YVnBmjOZS_LskEUgy9ZuihrGR9uk1NyJf_ddhfgiUqIERjbFPrzWRgFpkKQr78IOMvUlwRaEQO9H9_0mhEdOsO8rSxnv5HpcafrlhMC7okmIfWj2UOrcppU88yIn2SCwyvGFK94fZLjwyWOEYXa-dZQnXizS4cU4JZTR4z2lgfN4dKlvalc7bLjPgCOK_yJTTOBQ81se8tzTY7Q1TaRn3dY0lhO3EB-a5a85pLWCLg1G_xd8zjT6N0asBIjhkF_oOOqRAYtI8Vtd8GMPXko7IMBFzbHNw43wRKUEo7Q

http://s.m2pub.com/event/click/0/8CuIxLbMWijLR_oO-2_cUuMA6VabdNjv3yI_lPAfv3hxy5MaIsWRjqzWBdQAqe9kcWKv-Yo07fq45rPxHw24oClAuvTGbrTmvS1a0HfUNtCHHeHQBQYMeX_CyOs3pUXuvtBZsigSaok0y2tQh_ySW2o1EJqQfCfFEwWpPlAAlCemOla9LnL-BOSkNtmsUR7-jNAMCzVtNNwcaIbwdT4JmF9kQyTYsSj7I19GDhRLUhqDVrh-vUXh8ZryB5rbJUtbRw2YncwXhOmPy10A43LlazNE9bHjK_7IftiN3Brm2U5KLgNMmoipNH5FGIYlM5WOH6ywsk7Bc16Gj8xbAmVNmM4ET3B-5-p05Q1E-gY4ez-K4T5Cv8El/.../

http://s.m2pub.com/event/click/0/JXwAxRLzUxx3qKzsJ-Iz7bO7BP0mevXni2GwKCrkkmO8837qoeL2UKBxBZYY39Q1VmseARNh8b1SnZE_O-zJYGkGNQC7kDtB6dhwH2VraJBEzx7VOhdUGJzEf_g4tebmJJFDBvlZnDDbRFupKzLTM6avXJiCky_YEryydxint5HHtwDl7OXHUU9Wr8ij_nJQcyeUF4399i51Jy5EfcyiyMETTxmLhipyJLKYsXYPEbOqmIWOkYedyUFLqhxzB1e9VH6GyVxStzv8-ljS_Z8-PyhFOsqFtyuXPnRo8EB1So-RJucl6wvU6aXZKF6NQl6W-isnhmt8JvuZddeRRXK25QJt701nV-QZMW7egP9A8axZHQlyRwaD/.../

http://s.m2pub.com/event/click/0/PX4yZQeHUBPwQyMdOkPR5sKRqLH-EHLc6cQTytOIFWA09l8za6WjElEO0VYmNBw2EEvwfuMQQYLsJy4osQJXOCWwNiDcX_jzGw1RardA-o4MfZf1g3rhPbzLHFvsAYeBSbtaeW0wvWyCGAWPvfiNWVkg-3DtKEGHx6kij4X9MFq7lQgYV_EFLiNGOy3DM1WnGtWahoytGABKo7FZ2YKLH_Rn-93d-PgcJ78-xdEQ7hro1CHcuS-ok7wgLm540TB79u3RWmq06w2zBfOemhIktHpyQh-piuErXwcFI8VLBRG-JRIPPukIWssDLC0FfY6dnMtXjjGXuETvrD3O1IQNXByd7-iz3UwqntPiZ7I1_uEgH5mJPHdN8dp0CDIH6ijYuNkR0Q/.../

http://s.m2pub.com/event/click/0/kt1yEIusmG3XyUYvCy1EIh0CYHPXG_0LYrkhA5iCPyGwGPhPMU7ajJVXgctQoZYW-Gxh0H6aa1wpSKErGohjSdIWyIxORkJUBv8ZAb9gk53g333p-_sK4LvkU0zgdV26IAtGgNSSzdvcYdOd0vaAeqbXRupf8HrPMkpgU3hIgaGujIzAiRHgEgktCZ0MuUk-TH3X8pMf_JfyCfccC_QlPOWjvkAigDOZWfVjT0HWYGrSVbmW5GE6SBCoKDcYqYCg7wnozxYxn-2bRBD7j0qJKDRxGlQMiMsOuUuGW19afzNHCgsBb-AjCN8RZEOUd_qQCRvHawF5GRR6jvRINs8g5GeHvHLHTrm8vdw3rEJ_UkSPviNvBJI1sdxDqjr8kyYILQxbL2o/.../

http://s.m2pub.com/event/click/0/TgkzEGQQ3O-PCJ0qQbo19kcjrqJLZ5kUbhZYPdFVt00pZvvoj3Zo-wZEL235AqpIw8nLUIuMhmoAFaCAyvBXLzTVE7GFx87dkx4J0c-hRHdnMqkV3w3F5-tx-FNIP5jUg_FkJagdJrcH1VgtUCSepXFuNo4PAVyDCAS-2EEXT5VCbL9VBfLizX3144hXVyvMT39DwKplIlFp5MAE3SsfD4HlzhYgZKwx9-B9Bvd-n18SsyScGtqNejAeqv5lUeZcecl2Q6XGYcr91UfgF6mVtyIY_EdvfiCmCg1On4rCO1P2itvypoD1_NHY6yjIh0JMF1zJzQ/.../

http://s.m2pub.com/event/click/0/BrF8fpd87AiK8WmVVvZhcWZAmL1lyLt9GmifPaoIi64Nq5TMUCAzrUUB83qSxhuarX7MxYfPUbtGPSHKfw_QgTsAdOkcCsUZY12qSsYZk7G4TWNBy59DITBVcr8tZ1Jv9bR8DxcyQ57Z9nTGxfA7y5oH_yZfXdJc1MhyIiqpMvmZ8x_s6ZcLMuvS0GBZa73unuzgM_Wp7xTL95Oaq5ZlptFIwhJNSdRuIdpsT_xlgIJuOhgTs7F6jd-DsGNTx5m-aSSHNe7AZ80x4yaHA66TAhRfzsEsyVQ9Fe4fSmtbIgZMr-zmlGx5rhejDbAIT6tBowTcvw/.../

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=WTdGpEDvRqUPga1JlME_cAYtM8kc0A9wXG3Rarwj2x0v50jfluVLV_gil3SWHlS22DcCeVBnYmjjllYjh0dqICFHrmP0qYiju6srLhk_vm4mcB_X1WVvmWmxYj_TvGuMbPjkycXbYUr-L62AM6RSeeb8eCXvoM8AICFBD47S4Mtyadnx6BwQfRf5D3Px29hbiN0E2dxdDKgtBLeHjb3lcjaaG1OJRBTPtFGfgjTTW7nHXT2YW4S0wbjnWI-t8TQTtPxqGHQspWm-_iIUN4Ajgtc9xrbrvCYfVjnrx6AAlpkrIUZf1TJ0BX1C1QpUQqQPXEtkN1YKOtqN2NGIxv-7vLhuHjvxIefI3vbMR5-WXw83fLVdoK-bKw

http://s.m2pub.com/event/click/0/gT8w861W6jcUgiVKWn_q5fRWMwSxPh5Zr7yhwt6t-RZpyihH0jBkpi_4-HDdArncTuDNswkjho-ocEv_BbDQdZGY3vi_xz5LTA5-u7Lr_8_uJEbZcyHEhDhW3H43rvAX6-F6Ne1_FUFOlABIYrKgCGAoQJo-axwrXVpZyINptVPhK4se96Pa6f0tDhmMUW40gblk33xfJ_zBmv8CuN13XmW07jsUYe8-5WiXR3-qWRCJRz5O5pebQMwlIV1yJnyNNnJDk0CM6HuvBq8bjF79DWMB39J8mYCp51Sy7kN7f8x5JLF60QG2n9YHciMFgodknedoVJHwnste4O-cWzg1scGqDh3cp281-T77D5l6Xxd8suLtOQEGFg/.../

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=LiVqj1GFcPNICi8V6B3tbKn8TdlInLzwNRYcNpjUgXPtFQKZw0LhygkfTXR-kl4jjOtM9LbJEHvuiFMBjj2Xi9pw1nDH6Vjp-Y1Wk34XpG-iWN5Hsk0Pa0o1oJb6o4uxwT82ePV7GoaUMuhMck6IQZ8YMAJA8tejilkuSaoKW6ZgYSnyKujGaWLu-EizsuKSIvCS3R5Z9OHXtYd1TabQymnZ7r27oQychUMMu3AEWzDaJD7vl68fqwCSn2-7b7vbbI4bwBrxnchEA0AWumSFGPt9QRCNO3pzTDhWeIn_KihEnhpTek5BMnhq4Hs46_uY4pge8g

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=cKWabAY3hma3yujjA9TaU8s8StID8-01IaVr-Gg5ZF0ethHqS643q7VWQO2jE9M8bMn54qI0BjljcvXwMp7YnWrrqS-Afi1JjkeOelZTdmTa9klK0AIzaYwTF5k_NC010GiyGCUfkbfhFKpSPFMH2yBFt5XNU0d8w1oxmCtw95mK9BzWTrW9Hxxfnyv637_woUH3ZSm5Kh60nUSaEygjEdFGxbx0sAdS9lTh9ljZHEz4CZILRnbVn1o53zJKfIr2nKMYJ07SrsSyDPadqScZxM5bhricJGJ6HtXuuo9JgWo3Z-elt40XUfEC9gkpctx1ythObjjfOVIR9KvUL5fdKJRRfoRWtLBUJRpQL7nNNMPaH4cdhxB6Lw

Latest 30 of 188 download URLs

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security