AtlasPlayer.exe

AtlasPlayer

ITVA OOO

The application AtlasPlayer.exe by ITVA OOO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
iTVA LLC  (signed by ITVA OOO)

Product:
AtlasPlayer

Description:
Atlas Player

Version:
3.3.4.0

MD5:
339d48a4b0b1ea84120741930eae6a0d

SHA-1:
687659ae4974f00e5e3455ab4cbe66ccf9ce1b93

SHA-256:
cc723bb766ea2b4f928e619eb02d5f531ca7dc77128ee243a045d62c3ea08ebd

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/26/2024 1:37:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.iTVA (M)
15.8.23.16

File size:
10.6 MB (11,126,440 bytes)

Product version:
3.3.4.0

Copyright:
iTVA LLC

Trademarks:
iTVA, atlasplayer.ru, atlasplayer.com

Original file name:
AtlasPlayer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\atlas player\atlasplayer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/17/2015 3:00:00 AM

Valid to:
4/17/2016 2:59:59 AM

Subject:
CN=ITVA OOO, O=ITVA OOO, STREET=18 Koryakova ul, L=Saint-Petersburg, S=RU, PostalCode=194356, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7F3EBBC3A0970348263AADDFFB39E887

File PE Metadata
Compilation timestamp:
4/28/2015 3:59:26 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:k0Mz0OPp5m2RV7dxfhLt5jnnntOmUNbJAFgkNi1wCgnAWf1y:2zlj7jff5jnnnoLlAFgkNi1wZnAWf8

Entry address:
0x8728E4

Entry point:
55, 8B, EC, 83, C4, E8, 53, 33, C0, 89, 45, EC, 89, 45, E8, B8, B8, 2D, C6, 00, E8, C3, C0, 79, FF, 33, C0, 55, 68, 5A, 2A, C7, 00, 64, FF, 30, 64, 89, 20, B2, 01, A1, 4C, F1, C6, 00, E8, 95, 4E, 79, FF, 8B, D8, B8, F8, C5, C9, 00, 8B, D3, 85, D2, 74, 03, 83, EA, F8, E8, FC, A9, 79, FF, 8D, 55, E8, 33, C0, E8, 46, 41, 79, FF, 8B, 45, E8, 8D, 55, EC, E8, 3F, 54, 7B, FF, 8D, 45, EC, BA, 74, 2A, C7, 00, E8, 7A, 7D, 79, FF, 8B, 45, EC, B2, 01, E8, BC, 4E, 7B, FF, 84, C0, 0F, 84, C9, 00, 00, 00, E8, 7B, 5C, F5...
 
[+]

Entropy:
6.3887

Developed / compiled with:
Microsoft Visual C++

Code size:
8.4 MB (8,851,456 bytes)

Remove AtlasPlayer.exe - Powered by Reason Core Security