webplayer_fr.exe

Kreapixel

The application webplayer_fr.exe by Kreapixel has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from clic.illyx.com and multiple other hosts.
Publisher:
Kreapixel  (signed and verified)

Description:
Webplayer

Version:
2.5.0.0

MD5:
f6dedbc68eb9efd4cd877620b89c1144

SHA-1:
1cffedf0732e16caa7328cf200174aff818801fc

SHA-256:
c864c33a8cacee40a0f0ae3840f0af79b0b8a941e3ada5e93ad243e048a3dc8c

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/24/2024 11:04:15 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Crossrider.9
9.0.1.028

Reason Heuristics
PUP.Kreapixel.M
14.3.6.14

Sophos
Kreapixel
4.94

File size:
470.1 KB (481,432 bytes)

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\webplayer_fr.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/28/2013 2:00:00 AM

Valid to:
4/29/2014 1:59:59 AM

Subject:
CN=Kreapixel, OU=24, O=Kreapixel, L=Bergerac, S=Dordogne, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73E829C616F33571512B97CC95565619

File PE Metadata
Compilation timestamp:
1/29/2012 10:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Z6Wq4aaE6KwyF5L0Y2D1PqLiKvzxzRLXwx0m0:vthEVaPqLbhRLAxa

Entry address:
0xB9E70

Entry point:
60, BE, 00, 80, 47, 00, 8D, BE, 00, 90, F8, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file webplayer_fr.exe has been seen being distributed by the following 13 URLs.

Remove webplayer_fr.exe - Powered by Reason Core Security