uplayermediaplayer-setup.exe

Full Spectrum Interactive

The application uplayermediaplayer-setup.exe by Full Spectrum Interactive has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from network.adsmarket.com and multiple other hosts.
Publisher:
Full Spectrum Interactive  (signed and verified)

MD5:
b3d68741ffa87bf38e62b9de653035c2

SHA-1:
e10584680c27606e67dcf2c2f903997f9678f740

SHA-256:
cb084bda97e1e64a6ed7919af3fee3485e6f35f7dc81eaf7a510deea9e1921b3

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 9:03:11 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/DownloadAdmin.AH.5
7.11.120.88

Bkav FE
W32.Clod696.Trojan
1.3.0.4613

Dr.Web
Adware.DownloadAdmin.1
9.0.1.034

ESET NOD32
Win32/DownloadAdmin
8.9117

herdProtect (fuzzy)
2014.4.6.12

Malwarebytes
PUP.Optional.FullSpectrumAdmin
v2014.02.03.10

Reason Heuristics
Adware.Installer.FullSpectrumInteractive.Y
14.2.3.22

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14201

Sophos
Download Admin
4.95

Trend Micro House Call
TROJ_GEN.F47V1010
7.2.34

VIPRE Antivirus
DownloadAdmin
23896

File size:
576.7 KB (590,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayermediaplayer-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/10/2012 8:00:00 PM

Valid to:
6/10/2014 7:59:59 PM

Subject:
CN=Full Spectrum Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Full Spectrum Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A1AEF489C94F2C514EA16B9BEBCDEFC

File PE Metadata
Compilation timestamp:
6/22/2012 2:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:TYQxt2ctKQEGvjITZD+jcEckHnyudpc5y/zDnYDBrfw8Ar:TlxIQEMIT5dAzc5y/zUDBr0

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9663

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file uplayermediaplayer-setup.exe has been seen being distributed by the following 50 URLs.

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=hlge83HCgxWxAaAdvsUH4wk5Dps2UnTBxOhDn6oiKbg3_nTPasSJNo1AdRkU3_cACctH8NW9Ed9ngEawFNZt885QqJR9Mntjd9DdMy3AWbedqhWwLrMDXllZMhwMQdaLr4LCbaWU26mX9p4d3RTBZ2wgRiE1ktqGEE4kacrxGm_TwWes6H3YoM8CpTCR9RwzyXrdcXtD8EXtuKDrB-RVWchmD-tXvHpOnxPW-zb_RxBeoQv4e5AcjzhBmhXHa5uOhkesHPEc-zU-1XcKIB--h0-q7ohjcF-j8ebh1ZhSIiUYyta9SJQmIIw3itdSobDKHpsEtE2V4fdM_KvNqpgwwonl4VodkR41CxbQsaP6MmieKIFlAodZSEZD9GPUqGOZ4btpgMPWAWsuD1JX5LXtYWfOMYx9IC1MPg

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=xqE4guYR35yAEOkBiLY6vyn99szowU2xDqI5PfLHAMhGDxJToQhHYqhkraPTV50N0S9wY4qD4pNM6IBylYWKexAi-ltc0TVDnlTT2_7U2FCQYYkcfdBzUeLqWlCrHcEQfiAWQNsoxVZM61o9gFIFVPSzynKiVRO_D17o6eeFeadvPr964fy3XfGwER-mFlYylPej6Wkh8o16St8Dx8AyyEl-_d9IaPPiH-G3LG3AVHIWa_SPIvB4t9Mq4bmZxoQTARpDsRXBanGEUd3D7BF5MuXcCXIDdlnuvHbG-Tu1hVQY6AO-s5OJhrB_SjPbCBarG9CuBosWy-3n-gaxjZOuNBehAxXDFhKgwk9qahwqc9otVkOb84b3G8zdoEEG24lgnhk

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=171_2J-CDYBK0SvXf3cu7JmngGP3Db1OpVxSkziMDrMFYz9be8YuUvUzkigZXRUiCAxgMD4wZPCZX7kidDim3i_q0WnRM2It334fAkY9XFEogsiaoV8HdVEagJqnkBhV-6qsLUeHWIOEwOYbZuD2qSMtAgaT9D_tm84Nt5iGgORjkUUTIPhde6QQ65wzHJXX52WVrWFdX5F9Yaeex0b7MXuYLQ7DSn3HaAFdZ8o1bPcyjG1M1Fudqwq2G7oAx8GJE-arzaB8zfFXpkxphGX4dpOHZ7HcJf6P29bhgenh7mGuC-u1j15RwbxLOxEwYxS5mTD9bf4GzdafbYKnRR5b5DkpNNdA6CXnXFy4w0M5xtbJOTskEQVwJPRVgKPO

http://s.m2pub.com/event/click/0/1jQ9Ph3LyMHc4sKPEBJa0glgiB9QjJRopXSHGYfxgBk61OGrHbfT-mS3vIJ6dvSJiNTEyE_hUAoeBiZEv8Ej-ZXj1FH7ESY577o9pBAG1cgOeRvN8sKZtZhRT5yYA-kA20lkTaO0b5fFmnqSQW9W-KEzlZzSjgI46tKnQikTYOlSv-ELbztltQRvBglkdWQ5ogTyrP5fSfXce8i7nJtz9O6thBh9DPssotWVHlzIfKZdLsed8HCE2hgIkL4sjx_eCcya1gsT9MIoW1zQeNZ69BDd5va4bUvxKeGsueEgZ_rXfxwxlDi8Nyfvm9MUSzT5p5qOgSYqNvlqsQqPCdODnjAV26YD9fM37uc-FCtYq27AumbzAUOPVbJ9nVqP8EV2gRethPn1U9-fQhg/.../

http://s.m2pub.com/event/click/0/3ah7fRxtX5iRIVNXG2GkdFHy7KICZTzq3CaaG9z4cgqKh9y7CBby5OmnKOtwD8rXxDX2c8umGLGghpD93U4c44dhTMWLJT0863kmDhA2lm8DB3Iw09zQtkTeLRBrLLrJbFjdWZMPkbxsGjMWUPUUs8VpnefbHBXA9zyyHn58DfiCtDiRUSP3daK0IV9zxNVnMmnRa4Z34qhVcC131JEFb7HNGLjV9ZXoesvPjtYG0bEiNEASSMVEVJM9o--Dtv-4HgrWONdE3skdGsB-iDOG5gctyThWTFt1IJ05Mk2Vbo3AKsnbdXf2kXPa2QqRLcegGK4F6vp1qRfQEZnTFDnSlW0fHNHk41-pbUL24WuDGnWIP-OD1w/.../

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=17cXyRzPArK1uYdsQdGWBNaDUAUR_kcof3R4cZcInXhNVFbdSOZW0Z0P3CaulXj_lg4d-SHG5xwpmk4TxOwmCcSktb8e1P_iOFVvf-rE-9jPuz-tf-Z3GO8LMqy0DthCsKIY4tgPAhu9IYglfOFn3pJ0sZT_1hezaq43UOO0zJUgLCaVY0uJBATNxUWvyAF_JfoVE_EMKaaCizcPIfFE1hwrD1L3BZbqZTslEt7oGWKgYcasjyx1BsmMdhNoxnnoFjkssLuGCSD6Va1dyCxJoA2_bPNF1HyWe2aH8vxaD4Jy5-1tyjGodAiwBtkzd-pxSicxfNCKQldGtqE12B3GtVEURstC0NgTqWPE_CbXEqyQhWHVzTAi7FPp2OeiCU5m7-0oU0gjM_SPcHKOTlDtZPLnqG-Qmo3gSeB4b1ALsA

http://s.m2pub.com/event/click/0/ZThk9PMg0ZLoUZCMDdVxZCGDuGYXsU9lAD6FsqMkcQDAqPU8_VxEfOoGouqJtZRnL9U-jvmF-7ynYRftIjbDgCCyXc9x0mgF0sdlgrXJyzl3XtBi8E9jk76Spa0rHGFWjK1q7xJRBvHgEsIwrhYH8f6eeIZQpuwqWuG_KCCi7wGympCe3Imbj3OC9AQchJfSedPuUhWe7Mi0pDKCPA2R6rtFObj7YfurzJBXznFMDH_rTakg5SEdyUVxPj-cgr4MMmK0f35eQ_JEUGc3hmBJopFQRZ8whwH_sjOIODYtWJCFtKtUVepul9LGHkWR3mi-5gj6klKpC1KERhprEpXNmlImkzFSD7moXHTP44JKD1FdrTOBbF7vCCX4PW9b-H5j49AuXJw/.../

http://s.m2pub.com/event/click/0/YSAF9Q0yNWWhfzmbsY0ZpSMDspJqG51XQ7uImDDS16IyO2vDZGKJUcyHNMr01xCJIlkgPLmMRbE7mndbzAc8uUQfNNe5I1Cofx0EVW_syLbBzLKqGfOhLOeaqviUX2LCunokClgulBN87zM4U521DBfg9u7JrlBZANPq2vXd2PefDo0hS0zkhYMcVIOb4PhgHqBE3zMwurXkS8598KWbWY70QDw1eV4mtLtbnY621xpZB-YL_1hE55BkcKdVZjgxmKZCucv2gpgmsLN1oPhSLyRtIbIT7e1iqlghCCmAPlXq0wBT0AzQd9ww95eJFUHrJsksDq6H_tGbibY5CrpxNsfqkM8CS48ws7iVt8ZtHHDXJ2ZRWUUjpicYiNRjI-FSqBS58A/.../

http://s.m2pub.com/event/click/0/qzHi8LCRl-RTWciW2ZX78rkqqXgBdv48RTV9c_29g5xz8VBS7C_WmSQmPT25Jt_109TDDI7cDdmp87xrKO6K-APefwscPcy4sFTtc1rtGBGFt9AWJVQG7RU_2MjjqveSle_Z2E0yUj5CvlWXSPjQA53BGta8VVcm--OswEHhjyopGhigFJxT2JQh4RvTTyHYCkLJSy-JZ5ipQnnatwglMjpGmh3BOnRx2pTHfQm1Ovil3dB8BBzQwI1X_lPwJr-lvVa6n68-CM2U9CobGztV2FAp1VeBwNMZTE3LsYhr-wiDqB2p3wroJcrkSPmNauoSBQ2TLWBL9MkU7GszhMVODJRYDjNknPEh8NT1Dvn3QjdaDbwYLyIXMDqFXeSCRqhvaaE/.../

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=JnpZYNTYyJ_ZX05_qb8DeXJ5ovlUjkLd_Ix5XfSNncg0EgVBUV4iSenESx1PaCsnfsGVIQbCWtR1fjCpAlkxGZ_EpmL8UJrBq4IwLDVqkFUircq8F9rvHqyEWb4Y7i_o3GE70mXJ5GqVNxhfvwcvwre0tHpO3RtN0C-9LZYoN4TOrx3Ei2EGRKzzIG7J2OKBSLWgap6s1PwG1xKtuL2RP3Ut8se2GDiLliPvRywOmrRpwU7cnquQ6E6iroVbfCwkQDWNoWu0U30GvPpBcOjZEGKOxJBTRhgOloxt8-h9QYPrDXNugXg1BrnlDWFVRNG0j4Yn_mU0U6l2Y1xJ8L8FKdtretwn8-1EAzFIxwt2wVZ4sqvBDC73o-YJOaOCyqzMHgW6HA

http://ads.adk2.com/event/click/0/V9Qfta0UNOWbnTRw9ns_x62aTK10L7EDhs7rLZXp7-Ntd_w93XvCG_KxxGps7v7jtvZOVW6MFfafG1i5G63q1jaA4LhoHsgt8IoEAMHUDM_GrvOysJxRM5SmqBQGoMsdPvd9lW2F5SkTFzQqIjEYH2eVnqCGbv8sp4xlWGp_yLzk35x0rw5VbKcqHkisiZUB5vOE3lJQif5Z5T-C7f7zd95ei1Xqx0X7QkWNK8VTpLX-MsbZgQpcD49NfO5aXe-OaBknvaMXO4qcV8S3S8zYZ_W4DSZNxcXWDRnBm1wVnagRi4OcPoK7HpJ6rOUzpvrmXJzLeAx3dtQqgJWk_9L7I7eczVIrSmMEVgQwe8hAHWGOTnka38dcjd6bOXuOQ7B5KMG9nnY/.../

http://network.adsmarket.com/.../iWhvm2acqZWLaW-bX8p6w4iQappgooKYjGKYmWWee5uJkHGaXqF7w45icp5nnA?dp=-FYd3jQomzP1kUgE-K0iaxFwdgaC2v60hQQfjTjlzuNWBRG8tZXGm-mcfttmjlLHmORVyUyTZ01_H8HY_iiLRu70xLi2NfXMGZXJCsoH5XRks4YNYyKRZ2SjRezePVS9f5sNDjm2KY9wgrjr_h7SYsipxVBLgkGhHyXuc6zIupu9yJSZ-Lk4In9xD-ONktoJOwVq1WxSVeoBHT_8t_fJa7xH1w3djH7fWcmKxaOHo0okxme-EcHsNvjnWhR_alfT_RbCL5N98xpro5eiIyhgsY8NOrr0DYV-vlCvOFuH8ra7TzpajvcMWifldCFDhbwwd2VniqVNCfwiQnbki_yWvR2HIYA2ZiXIAC2ABsIMUY39FcCehPgjvSTQesMbIDjRyRqkMUOX_u52x6m6HGoZJxGc4H2qKbfpsbOdbzLKdlA

http://files5.mirror2.info/dl?bc=919437&aid=176681

http://s.m2pub.com/event/click/0/jmlpIo9EYq611wg4lQlDHXYhC5hD9koCxgEzjxZO0--zwM0H0i_r8zKFgcn127ZV-RfbgDT6CRjCjhw7TJF3jCGKTk85ID5dEUnBWAfeUh__hNcI5rRiH41wY5DWtzkerTURWMWCyAsJOh8OqUEqT1rn2jmtBiDB4dnvkXw0kT0j8C10ScZc5uIcL9YK_S47eJC9moYFVKpX4PPyyitjVr6C1220Ve2Go1KxA1xn1J0oB27dHDcypzfbdKRzDjB1FKF50ph5ybKHZYoAqpVyI1I2tv9D6jQ8ziHh-AUGf7G82JCG9H73aMumgrcKbQa3kx32iY_KisWVve1LmSueOFz95JXf8giNaFR5UaL-HTaSjaOB2sCGruqz5DRm1fuX2Q19VOTOSVA/.../

Latest 30 of 115 download URLs

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security