vlcmediaplayer.exe

The application vlcmediaplayer.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from filez.kappa.ro.
MD5:
870e0046d15bc6e37e9898e2df634f97

SHA-1:
d79f2f42dff71df8bb7581351f9548279b6caa84

SHA-256:
7628a238fdce57e8952bad9876b897aec2a36c7b4bdf51090125fe7d40b3e335

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/26/2024 9:59:48 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:Ezula-AN [Adw]
2014.9-160110

Baidu Antivirus
PUA.Win32.InstallMonetizer
4.0.3.16110

Dr.Web
Trojan.DownLoader5.31721
9.0.1.010

ESET NOD32
Win32/InstallMonetizer.AN potentially unwanted
10.12518

G Data
Win32.Application.Agent.UZ9RBO
16.1.25

K7 AntiVirus
Trojan
13.212.17753

McAfee
Artemis!870E0046D15B
5600.6525

NANO AntiVirus
Trojan.Win32.InstallMonetizer.dttvjb
0.30.26.4437

Sophos
Generic PUA NH (PUA)
4.98

Total Defense
Heur/TrojanHorse.ZCIA!suspicious
37.1.62.1

VIPRE Antivirus
Trojan.Win32.Generic
45010

Zillya! Antivirus
Trojan.TDSS.Win32.44552
2.0.0.2494

File size:
2.8 MB (2,908,942 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\vlcmediaplayer.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:pfDH709caVjMhOqfP87+uDe9JGhtMolnVeQokmoTW9HvW5XDgbBJSov:pD+cGjMhOqfwmizMoS1sW5IT8nSy

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vlcmediaplayer.exe has been seen being distributed by the following URL.

Remove vlcmediaplayer.exe - Powered by Reason Core Security