webplayer.exe

Webplayer

Kreapixel Network

The application webplayer.exe, “Webplayer Setup ” by Kreapixel Network has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from d1pg43ots40sgg.cloudfront.net and multiple other hosts.
Publisher:
Kreapixel inc.   (signed by Kreapixel Network)

Product:
Webplayer

Description:
Webplayer Setup

MD5:
d2bc679293e41d474de30fd6e5883df2

SHA-1:
b372dd683916292faf72d036f0e22d3212a7acbf

SHA-256:
abb32731bf82a98d91453cda33a24d2f4804aad30d950700169bdd9efe12ce67

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/27/2024 9:45:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.KreapixelNetwork.J
14.11.21.23

VIPRE Antivirus
Threat.5064134
34232

File size:
353.2 KB (361,664 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\webplayer.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/27/2014 2:00:00 AM

Valid to:
6/27/2015 1:59:59 AM

Subject:
CN=Kreapixel Network, OU=24, O=Kreapixel Network, L=Bergerac, S=Dordogne, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
08C337D1809F41539363BCF60D881AB2

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144://QiQP/pNbRCEMrwTPRA6dYdyY+ClC1JaHS53gHoGJCKax70Z7:3QiGB5YEcwe66drvC1Ay3gIGJCKk4V

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file webplayer.exe has been seen being distributed by the following 2 URLs.

Remove webplayer.exe - Powered by Reason Core Security