chip_downloader_vlc_media_player_2.0.5.exe

Chip Downloader

Simply Tech Ltd

One Floor App (Simply Tech/Widdit) distributes and bundles potentially unwanted programs (PUPs) using its OneFloorApp install manager (SimplyInstaller). The application chip_downloader_vlc_media_player_2.0.5.exe, “Chip Downloader Setup ” by Simply Tech has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Widdit Setup installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Simply Tech Ltd  (signed and verified)

Product:
Chip Downloader

Description:
Chip Downloader Setup

Version:
4.4

MD5:
03a8f0bc473633b5863088790c778172

SHA-1:
717d85bdcb1d200695b3378b5581d1e685cb5f29

SHA-256:
8bb942720cddd189dce134db57596cc77b4925740b975e9bdb24e77bd3e7be5b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 12:11:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Widdit.SimplyTe.Bundler (M)
16.7.10.20

File size:
656.1 KB (671,840 bytes)

Product version:
4.4

Copyright:
Copyright (c) 2012, www.simplytechltd.com

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Widdit Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\chip_downloader_vlc_media_player_2.0.5.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/4/2012 5:30:00 AM

Valid to:
4/5/2014 5:29:59 AM

Subject:
CN=Simply Tech Ltd, O=Simply Tech Ltd, STREET=10 Zarhin street, L=Raanana, S=Raanana, PostalCode=43662, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FC78D842B3886BB8D32517578F7489C

File PE Metadata
Compilation timestamp:
7/9/2012 7:11:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:j3MjhnX888888888888W88888888888wzKWY2fHMiwSH+BAN63gj2um7wCfl8RVZ:TMjh+1x+BW9aeVneOH

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B8, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 56, EC, FF, FF, E8, FD, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, E8, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.8093

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file chip_downloader_vlc_media_player_2.0.5.exe has been seen being distributed by the following URL.

Remove chip_downloader_vlc_media_player_2.0.5.exe - Powered by Reason Core Security