finalmediaplayer2014u1setup.exe

Sak

Locat

The application finalmediaplayer2014u1setup.exe, “Sak Setup ” has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.clearpackagedownload.com and multiple other hosts.
Publisher:
Locat

Product:
Sak

Description:
Sak Setup

MD5:
e3c508fece3ad55136ba9b8303eb1cf3

SHA-1:
3215cb7f9e6e17c618dda19b7a7edb36f5d3b267

SHA-256:
5fca83792ed9c2cbc4452c37be9aa96911b017dd726df8ec1eeef388f6abfbfd

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 3:50:24 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.ACY.gen potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.InstallCore.RE11 (M)
16.3.7.2

File size:
1.1 MB (1,164,316 bytes)

Product version:
3.2.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\finalmediaplayer2014u1setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:kCzSuQK2mOouEq50eNKMp7hkats2COTy7WlhJ0FzGjdD5wc8oyQTd4XT4j1jl0w2:kCzMK2mOo0TgAkaS2vnl7Sz0dFwrb843

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file finalmediaplayer2014u1setup.exe has been seen being distributed by the following 50 URLs.

http://www.clearpackagedownload.com/c?x=2V0ie55VramkzNE2Lxe9KIZQ11jAMYH bLpY2HJ4cPE=&c=9i zIqkzmdbGyHlMfaQ7MdJbEO2fwC7qp4iFof4b7IM0WG34xtRJYT4YPe43bEbeQz 61cGyd8xVqwyWo8pW2WyX8Fc2UzxSalvhcROwYliH8lfWd4ARWTLb15A1wLrO3tvMjcnepzfeTlCBPBLxO6DzSxoKQ8px6pYw4S300WBPVPLFbwZqR1aGFdMGXVVR&e=0&downloadAs=FinalMediaPlayer2014U1Setup.exe&fallback_url=http://www.finalmediaplayer.com/.../newest.exe

http://www.stockcentralsign.com/c?x=tgx3Hwme1mMcRtpECA5kyLZ sqVuMOzsSx1gMO3dW8Q=&c=9PY63m2ePzwk/zD5R9DgeHXfapiEcPdKM2LY9bjet8Lz8XEXK9HVCDqrIYMgESkoqddia4an7UYRxvHQEvKScbgqDZpqKMMTzJumPKjaMK7sK6O5qnJedOnjOWkaIpCDt8DPmFTTm N68KjtUtKfRp7fdnLNA YYxKKmxJ1VrK3nnlN7utF3hkR fDzfjsAc&e=0&downloadAs=FinalMediaPlayer2014U1Setup.exe&fallback_url=http://www.finalmediaplayer.com/.../newest.exe

http://www.towersoftwarebundle.com/WVl6OTRQVVZyVG1sR1Z6TkRXRUpwVTFReWRHVk1ibTVrZFZSME1EVm5jVEprV0hSd1kwOVlNM2x0WVdoU01qUWxNMFFtWXoxa1lrOGxNa0pMVW5KeFZFUk1OalpaV1hGSVFVTllWVTkyVFV0bFRqTldNbEZEUkVSc2VucFFRU1V5Um5ob05XTTRabkJTVlVFNVYxSjZVRll5YVZSTGJFMVpkRGRuUkVscFZIUTVaemwzVUdGc1duUWxNa1pRYVNVeVJsRTBhMmxEZGtseFl6UkplRmxxZHpSblFXNVdlRFZ3YVRoTldrMVVTM2w2TkVwSU5XZFhOU1V5Um5SMFQyd3lUbXBYYm1RMGIyZG9lSEJTWTNGWGRGWkRUekJCSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBVWnBibUZzVFdWa2FXRlFiR0Y1WlhJeU1ERTBWVEZUWlhSMWNDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ozZDNjdVptbHVZV3h0WldScFlYQnNZWGxsY2k1amIyMGxNa1prYjNkdWJHOWhaSE1sTWtadVpYZGxjM1F1WlhobA==

http://www.bodysignsheart.com/c?x=fiTJJi1bFGnwIwZaEtZ6O5czNfABsODYsqwQe8yg1bs=&c=0Zp7lHzCLN0TgqX6rKPV kRTDd6AQmIz9PTPFe8ilZRCmZwDeSxzqIdgIE2uR3s/ e4LcA/jzMSChuw/ZH3oEMWoZuFgC PKd7sFN1OiWonv5bxrd7SsZkAhBdzfLbqr5Mn51E1mTmBoBFRxmM3y11T56VNF3 OOYh5Rwi9kqtbExbgeEoBXIZabyXNOsr8I&e=0&downloadAs=FinalMediaPlayer2014U1Setup.exe&fallback_url=http://www.finalmediaplayer.com/.../newest.exe

Latest 30 of 125 download URLs

Remove finalmediaplayer2014u1setup.exe - Powered by Reason Core Security