webplayer_fr.exe

Kreapixel

The application webplayer_fr.exe, “Webplayer install” by Kreapixel has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from clic.illyx.com and multiple other hosts.
Publisher:
Kreapixel  (signed and verified)

Description:
Webplayer install

Version:
2.0.0.2

MD5:
998349aea9856642a0235cd339f4aa2f

SHA-1:
1176a096cfcad9d18bd3ca144c09bb7cf514b0bc

SHA-256:
977199c4d39a03c1c22824dd510f7c6b335fb96155ae4f204f3a9260abb6effa

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 7:23:52 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Crossrider.9
9.0.1.0113

ESET NOD32
Win32/Krepixel (variant)
8.8993

Reason Heuristics
PUP.Installer.Kreapixel.M
14.4.23.10

Sophos
Kreapixel
4.94

File size:
505.1 KB (517,176 bytes)

Copyright:
Krepixel inc.

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\downloads\webplayer_fr.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/28/2013 2:00:00 AM

Valid to:
4/29/2014 1:59:59 AM

Subject:
CN=Kreapixel, OU=24, O=Kreapixel, L=Bergerac, S=Dordogne, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73E829C616F33571512B97CC95565619

File PE Metadata
Compilation timestamp:
1/29/2012 10:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:6uIlWqB+ihabs7Ch9KwyF5LeLodp2D1Mmakda0qLk63Kaa257qYwTMryxWfiBM:R6Wq4aaE6KwyF5L0Y2D1PqLf1axtxPO

Entry address:
0xC9E80

Entry point:
60, BE, 00, 80, 48, 00, 8D, BE, 00, 90, F7, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file webplayer_fr.exe has been seen being distributed by the following 10 URLs.

http://clic.illyx.com/aff_c?offer_id=25&aff_id=1017&source=streamovie.tv

http://www.mangas-garden.com/.../

http://clic.illyx.com/aff_c?offer_id=25&aff_id=1383&source=movistreaming.com

http://clic.illyx.com/aff_c?offer_id=25&aff_id=5996&source=www.dlstream.me

http://clic.illyx.com/aff_c?offer_id=25&aff_id=3644&source=filmze-fr.com

http://clic.illyx.com/aff_c?offer_id=25&aff_id=3668&source=filmenhd.chez.com

Remove webplayer_fr.exe - Powered by Reason Core Security