vlcmediaplayer-setup.exe

The application vlcmediaplayer-setup.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This particular feature is designed to hijack the browser in an attempt to prevent other resources from modify the browser's search and home pages. The file has been seen being downloaded from files5.mirror6.net.
MD5:
347e49c7d2ad9d1dbfeaa4cf5fc9496f

SHA-1:
cb1f41d08aa131a388718ccad83e1b30ebc17ac1

SHA-256:
d931685863bf38410c2b7e0eca1c64b624f27cbe9ecec5cc6c57201300d52a23

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 2:06:19 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
7.11.166.78

avast!
Win32:DownloadAdmin-N [PUP]
150717-0

AVG
Generic
2016.0.3001

Dr.Web
Adware.DAdmin.151
9.0.1.0242

ESET NOD32
Win32/DownloadAdmin
9.10230

F-Secure
Adware:W32/WebInstallBundle
11.2015-30-08_1

herdProtect (fuzzy)
2015.8.30.21

IKARUS anti.virus
PUA.SearchProtect
t3scan.1.9.5.0

Malwarebytes
PUP.Optional.DownloadAdmin
v2015.08.30.09

Sophos
Download Admin
4.98

VIPRE Antivirus
DownloadAdmin
32080

File size:
912.6 KB (934,512 bytes)

File type:
Executable application (Win16 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\vlcmediaplayer-setup.exe

File PE Metadata
Compilation timestamp:
6/17/2014 11:35:36 AM

OS version:
5.1

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:nxpJMyVWJ0q4kfS6wKhmcRf6vEh7+KAFgtp51idtDWEqOWtVr2/NoPH48:xpanJ0ZkKIh7mFgfidtDWEn20/No

Entry address:
0x3341

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, F8, 24, 7A, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, 00, 24, 7A, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, 00, 1C, 7A, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 80, 7A, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.5051

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vlcmediaplayer-setup.exe has been seen being distributed by the following URL.

Remove vlcmediaplayer-setup.exe - Powered by Reason Core Security