uplayermediaplayer-setup.exe

Full Spectrum Interactive

The application uplayermediaplayer-setup.exe by Full Spectrum Interactive has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from network.adsmarket.com and multiple other hosts.
Publisher:
Full Spectrum Interactive  (signed and verified)

MD5:
26603db6fcfa0943e7e51abfa8eb502e

SHA-1:
d34c4c33d11dc7e41988058d2d43ce2962fa3216

SHA-256:
0d5544add24daf8c0c163ebca225dd39ec7bcf7ddcad454152655a9cb8d38433

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 1:26:31 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/DownloadAdmin.AH.5
7.11.121.86

Dr.Web
Adware.DownloadAdmin.1
9.0.1.0364

ESET NOD32
Win32/DownloadAdmin
7.9190

herdProtect (fuzzy)
2014.1.9.12

Malwarebytes
PUP.Optional.FullSpectrumAdmin
v2013.12.30.01

McAfee
Artemis!26603DB6FCFA
5600.7265

Microsoft Security Essentials
Trojan:Win32/Dusvext.A
1.165.247.01

NANO AntiVirus
Trojan.Win32.Downware.crgjbr
0.28.0.57029

Reason Heuristics
PUP.Installer.FullSpectrumInteractive.Y
14.2.17.3

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.131228

Sophos
Download Admin
4.95

Total Defense
Win32/Tnega.QQVEdJC
37.0.10655

Trend Micro House Call
TROJ_GEN.F47V1122
7.2.364

VIPRE Antivirus
DownloadAdmin
24644

File size:
576.7 KB (590,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayermediaplayer-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/10/2012 8:00:00 PM

Valid to:
6/10/2014 7:59:59 PM

Subject:
CN=Full Spectrum Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Full Spectrum Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A1AEF489C94F2C514EA16B9BEBCDEFC

File PE Metadata
Compilation timestamp:
6/22/2012 2:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:TYQxt2ctKQEGvjITZD+jcEckHnyudpc5y/zDnYDBrfw8AJ:TlxIQEMIT5dAzc5y/zUDBrW

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9663

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file uplayermediaplayer-setup.exe has been seen being distributed by the following 50 URLs.

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=LUmXlLiYHEvOO9GHvEcEdImE4nUkdZJ1Cs-ckzNLy8KAl-s02rJzoSJpT5uhnMXdx8uXl-hPn0INX_wDxXRjHiXgQ4IwL3ZoPm891cJpp_dyKHUwT-c0hR1cADB8I-MsxxDW4f6rQHAqHhH54rQNOQ-MwEG98uBNMBd4PBsQh0vf7yK7OjE_eLGeQHp6DlKAjBb0Io6NWhsLR21jeoHzUUaC7lvHu1Un-mj8dirBzxqByVGx8bn2P4P3N2DlYPybUaZTD9rrVan5LMajSvx2_wNAz4pRejLFNgxETY5yjIhGmEzaivBBqaIZd_vErOzhg6_4OYBlQhGiILlkTxmbQrghQ6jZAcHytq75YdJPPBL4c7MRpSSL2PMmxFY

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=H2jHYkiX0i6KbVO-fevTb59Ata0tXOlZRue-wcg0Yyq1xDXjhpeyIfk_hiZVOGAzhYeH_75jNTB4y7-LGsyQqxG7rEzdvC7cGjyVGQlkfEqwM7fVQHuvh6o-cBrmB4Q31sKohjYvTJhMXV02KuRNkqzR9VaKfW4-ET9mscAjiajo8-n_wSEJObqerOVeG8fkkUurS1E__5Kn0VFdQd9QLa6zK16HQTFDT7eF7IAL_H-L_W02nvFE7yBUwTDn-t2CA-R3nxcXYQdrnlUOfR1UKtaeLqicAM7LLltPjqCmewl53CNQjHngbfn0bdQr-1eMhy3BS7HLL68MD3ULUK9xBM19ROqmI7KHylsMfJ4FaZFiEZXOi_l7nIcaxPlc5WcJX2GPbOBDM3wG

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=Q-1p7ZaZk0X1JvIB1CvSHgtw1IUHuoF2FJpaRquOwwM0ypang7qq29aN1oLXOiJW85irc6rP6YiNSyffIbGuxqYcRakd0pCeCeYXJO7Dw83wCGI4fSbON83EqMr89_FwEfMwysJMYVZc_zuP91Xm09vBzf9i3ax2ysRbO7bMxFCAToG75Z4PJfEyoQ8AvuXv20YweRXutDkatBl19iCnvEJUM4qMyQUP7ONSiYXQKr5vgs-x3V3GnluJBe5Q0tYiTiAZx3pcgOAeOp4zPs7Gf2tR-hQdQTrbPuNaO5lxjLxVXN4w22DhFr7PfGMNPye3MdMIlv05XHEiy04_Q1rPTQDZIkYdVnhvV9ZJCMDEk2OE3IUeKkfA9Pps3ra4W_Eup2OGCsfX7l_4

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=eZyYRvikRqv3vkqaVmiqKMN-HOPigYwOaG3cop__h1ITUQtrpovhzPvqG6QdwnUxrDminvCfVZOqmUoNvq3JntKyNY2bd99nY2OR3R1VDB7LH4i59CNhRE12ZWz4UzPRASpGJTu5WBPLmUWB_MvAqSOvvdHc2ARTM7a9FHhQGXLuoi_bsBklnaGNGkc-PFmQpqtg3qwKv4YRrb6THrfhFOjXpoIGrA8jB_nifrmczSgHhHGqdr8wvOL-cZVoZJKh7Wod7RRpS8i3QIKWCkzrdboJhs-bDFhBH7oYjckQV6yUMUwjfhGPQzlXvytX4p33_P-I2UqTHIsuGQ2TdBH2kdrdawXgN3FcretxyokbHVe1L62fcMVTc8eIPKU

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=_Mpt5cMPWHLD-BtgquDDJPLJJigiPrcyjQjhWlQr2GGXMpUgthHhw13W_pI5fPCZD6kqY8ioExETYGw9y9qxU415yyFhr8JxBeGc9PxIMPbCMtwpmoR4RCDFFZy8nZjxxdfKUhc_-QeH61luraEvP_679LodPxOM6ZDkbg-inob6DL1VDTfW6X7eqIouJf-PSge3x7EhBLwGrq_ZtfC-hK1n2pxS7IL6ozAc0KoC13tiL301DWF3vwDQ16ZSGMHWvGmDEGr2GdKdcddtuWMnBcnju3_PYyt00cHZcRfQtgOlobnccwb4D8baPzjK7VbjIJ8z-zSiFbnguX53ak3X0AFDy_3-eeMp_5h-M3TqGXzxSNHawR6sVdzNZFze0K18AfpOcjfq8h74

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=rPY2Oy7Jri1tx6cu4ll9EXvV693haWhrZ2jN5iknzj1SD_NufOZ7popM3_d9XricmYerCCL3yTXpLcA5bIhwA8hNPKpTbRlXHPkPvloy6ilwsEjtryiRrpBO1ICJNPNDhih_FTkB4sJdwhHMjpGIqtNyEa9RciM0krbTgvs29xt6UaZPhf5c6Aq1agqlZOCx0m0dpy-AKWdkjc3Z33_R4LBvT6zEc-LMf9rvcaHiNSivK5gWBOT-bNP7ISUgC9-GdfI1tmljsD1dyh-NCvSztd52k4JCjRFeytxaMbXzCTgrPcZLgRRrCRTnxzxRpgYKdlXko-JL62JLF5BEa32MDHoA7DXCslAQQn6pEvCHz6z0OUV9oPaJUlSOBFyoR4s_yZzrEwHu

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=cLj4hgU5bpNLR25dae_cL47mJX16HVWVhn-h78RLnoiKYlkJJsw01VR45LUow_Vc5dBG8R0MouRKguMrBYi5K0257NPhHbO3VIGzLzWAAZJRyxXey18gkK68YOPphJiVCdI9hZ9rWZKjN2Z4pZzc1trjZ6eBa5yiC0t_mpHKq2RssE3U5tylFrxjgNQ7j-geOvoS2svpt2_uRNnphLmvBMxQserM8JwgJmUbNMvUQ6hpGOqUuL-dXl3v44f7H4ijEP0kt00ac2J2xYFfTJL0WHh97LoJMktY-f-JFuGTP4tAf5AUrxx3GH8Bh6r_MKsxyJb0Vqe9heXwRpbuk-AQfnY9ruLMrY6tUGM7cYdGBfmEO3Ou8CWEWHw12J9sFwkMVTBWxVxMbnay

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=_RND8WUQJmsC3oQVpytAM3lDYCNzMDguGB30trqnaX-ORGsRe9UUv4qtMYJFncZ7C9YZJwff0AtSEBj0aWm6_BBBji9j9BM64JP4FGaANV9trpHn-hVDYWQc5tsRINGh44_HViv05NWOhdIT1AnWPoqyxuhdBqDEFlFL_FLBW94oJ7d3et5ENpJvrQYoSBcKZkYrWx_is__b3sr5NJN-Bnz3WEAqvt6DbU_3mvbRh7pk-nc5wwbXWldkx__zGdmhj5oaHyQof2q2UYSP2RA2rrGYnmQ5Gx94ia4MHTmvhIE-hqEssDGuINGrnSb7PKeV-wE3rxFc5l4cyqTr64nynwN8mUDYAzP-HaaZmMH6iU5xH55r55OrSXTLVYbjgd7Mk_-wHmERi0o

Latest 30 of 73 download URLs

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security