vlc media player setup.exe

WeDownload, Ltd

The application vlc media player setup.exe by WeDownload has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars. The file has been seen being downloaded from vlc-media-player.xtremedownload.com.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
92cf7e22db463d56741c2e5416be834e

SHA-1:
2cb86cfbf6a17cc6a338cc1a57052e73565bc336

SHA-256:
04488e185f063869548c8bd4635c8f3b48b97c8c1fd9b34f86cb8723a9bea86d

Scanner detections:
14 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 4:53:07 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.164.150

avast!
Win32:Downloader-TOV [PUP]
2014.9-140320

AVG
Wedownload
2015.0.3389

Clam AntiVirus
Win.Adware.Outbrowse-2
0.98/19185

ESET NOD32
MSIL/Soft32Downloader (variant)
8.9557

G Data
Win32.Application.Soft32Downloader
14.5.24

herdProtect (fuzzy)
2014.5.15.3

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.03.20.02

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.W
14.8.7.20

Trend Micro House Call
TROJ_GE.0ADD1E3E
7.2.79

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Soft32Downloader
27502

File size:
593 KB (607,192 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\vlc media player setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/5/2013 4:00:00 PM

Valid to:
2/11/2016 4:00:00 AM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:rwMDD4yOtJVrfyDL3xcqXIHBC3OLQjPHyEOOym:rtgyOjVbyHJXkuOL2SEGm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9166

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vlc media player setup.exe has been seen being distributed by the following URL.

Remove vlc media player setup.exe - Powered by Reason Core Security