uplayersetup.exe

Full Spectrum Interactive

The application uplayersetup.exe by Full Spectrum Interactive has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdn.uplayer.us.com.
Publisher:
Full Spectrum Interactive  (signed and verified)

MD5:
85374048d0316696eccba5ffb436d717

SHA-1:
a41b70ca4dcb40db10b240541ce3aac73cc41755

SHA-256:
680b4fea1d2d677788b164338acbb5cd7f6a8561bee15a372e629a276c7d9279

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 7:11:00 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

avast!
Win32:Trojan-gen
140908-2

AVG
MalSign.InstallC
2015.0.3340

Comodo Security
Application.Win32.InstallCore.BWAN
18095

Dr.Web
Trojan.MulDrop5.10078
9.0.1.0268

ESET NOD32
Win32/InstallCore.JE.gen (variant)
8.9670

F-Prot
W32/A-dbe1ec51
v6.4.7.1.166

Malwarebytes
v2014.09.25.12

Reason Heuristics
PUP.Installer.FullSpectrumInteractive.M
14.9.25.10

Vba32 AntiVirus
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28212

File size:
673.6 KB (689,728 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayersetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/11/2012 5:30:00 AM

Valid to:
6/11/2014 5:29:59 AM

Subject:
CN=Full Spectrum Interactive, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Full Spectrum Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A1AEF489C94F2C514EA16B9BEBCDEFC

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:NvpnQL69qHPi0/q+JMuvX0PmyeOXCUchCIeTvkcaP2R8tnNCedL0ZZB:NvVQuqHq0rJMuf0Pm7iCUchCLaP2R89M

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.7837

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file uplayersetup.exe has been seen being distributed by the following URL.

Remove uplayersetup.exe - Powered by Reason Core Security