vlc media player 32 bit - chip-downloader.exe

OCSClient

CHIP Digital GmbH

The application vlc media player 32 bit - chip-downloader.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
CHIP Digital GmbH  (signed and verified)

Product:
OCSClient

Description:
CHIP Secured Installer

Version:
7.00

MD5:
99ece33e6b73372c6b37a9b61e9c1a07

SHA-1:
23a12845588ec941e63c6eb8f9fd963ed8521a01

SHA-256:
7ade17756ce8b679741a0a8e02bdf54273dcf8d83943d5e671fcffb4d75a4ebd

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 9:52:12 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.1.21.16

File size:
600.4 KB (614,784 bytes)

Product version:
7.00

Copyright:
Copyright © 2014 Chip Digital GmbH

Original file name:
ocsclient.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vlc media player 32 bit - chip-downloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/26/2013 1:00:00 AM

Valid to:
11/27/2014 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, O=CHIP Digital GmbH, STREET=St.-Martin-Str. 66, L=Munich, S=Bavaria, PostalCode=81541, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
360BEAFE1EBBCC59FBA31179BE3192C0

File PE Metadata
Compilation timestamp:
1/15/2014 3:02:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:1KWlw1DxDOASIAfCEv2YUMNJlaJuNlK17Y4c83fhysVufBn597NX2t:17lw1Dx65zfXeYU43fiysgfBnnl2t

Entry address:
0x1620

Entry point:
68, 08, F6, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 6C, 51, CB, CF, 4C, 39, 05, 47, 9B, A7, 1A, 8F, 7C, 78, 87, FE, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 4F, 43, 53, 43, 6C, 69, 65, 6E, 74, 00, 34, 36, 7D, 23, 32, 2E, 00, 00, 00, 00, FF, CC, 31, 00, 03, 76, 0F, D7, 04, EA, F7, DC, 4B, 85, 6D, 25, A8, 40, C8, C5, 30, F6, 07, 2C, 55, A5, 90, CA, 4A, A7, 78, 6F, 37, 88, E2, A6, 56, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
96 KB (98,304 bytes)