vlc media player setup.exe

WeDownload, Ltd

The application vlc media player setup.exe by WeDownload has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. The file has been seen being downloaded from vlc-media-player.xtremedownload.com.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
a76d97e447871333b1f2f7316c95d006

SHA-1:
74613963616f56594227b62f14797a7ec8f5159c

SHA-256:
c590a20b52cdd71d4f77bd8a2f882bb7dc1a735aaf071031be588467f757c771

Scanner detections:
15 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 12:21:29 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.174.72

avast!
Downloader-TOV [PUP]
141025-0

AVG
Wedownload
2015.0.3309

Clam AntiVirus
Win.Trojan.Agent-754117
0.98/19424

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
7.0.302.0

G Data
Win32.Application.Soft32Downloader
14.10.24

K7 AntiVirus
Unwanted-Program
13.183.13476

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.10.26.10

NANO AntiVirus
Trojan.Win32.KillFiles.ddsvpt
0.28.2.62286

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.W
14.10.26.22

Trend Micro House Call
TROJ_GE.582CF559
7.2.299

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Soft32Downloader
29198

File size:
593 KB (607,248 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\vlc media player setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/5/2013 7:00:00 PM

Valid to:
2/11/2016 7:00:00 AM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:FwMDD4VAASas8t5o6ESfqK+MxfBwOWYp7i72NQ5CH9o5+V+ixm:FtgVAJ3nSfqK5xfJiS5RV7xm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9168

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vlc media player setup.exe has been seen being distributed by the following URL.

Remove vlc media player setup.exe - Powered by Reason Core Security