hdplayersetupit.exe

HDPlayer

HDPlayer, Inc.

The executable hdplayersetupit.exe, “HDPlayer Setup ” has been detected as malware by 11 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from kplay.trade.
Publisher:
HDPlayer, Inc.

Product:
HDPlayer

Description:
HDPlayer Setup

MD5:
8f09285ad06dd20c325e1cf22b33bb87

SHA-1:
2bf6c9b82deea558edc6da90ecb83bde9a8d1d29

SHA-256:
b5878de4e623e40141436c7764609fbae6caadd5bc60df0d29df676ac24d0b33

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/17/2024 11:47:44 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4604

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2886.0

Norman
Win32.Sality.3
22.05.2016 07:18:28

VIPRE Antivirus
Threat.4721115
50222

File size:
3.7 MB (3,899,091 bytes)

Product version:
2.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hdplayersetupit.exe

File PE Metadata
Compilation timestamp:
4/6/2016 7:39:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:paV13MPdSErEL/XNUH8C0mvg0DxmKierYC6FYan9klqLxjX:pm13q1crz01mKierYC6FYiMqLxj

Entry address:
0x117DC

Entry point:
84, FE, 23, F9, 8A, E0, 8D, 35, BD, 1A, 2C, D9, 8D, 35, 87, 2A, 03, B4, 8D, 15, 78, 5A, EC, F9, 8A, E0, BF, AC, 05, 31, C4, 51, F2, 0F, BF, F2, 3B, C1, 59, 31, DE, 85, F5, FF, C0, 47, 20, CB, 33, E9, 87, F6, 88, C6, 0F, BF, D5, 73, 04, 28, D0, 38, C1, FE, CD, 87, EB, 13, CE, 4B, 0F, AF, D8, 0F, AF, FB, B8, 47, 0B, 00, 00, F2, 35, 0F, 05, 00, 00, 85, ED, 76, 07, F2, 69, F5, CE, 08, 84, 8F, 69, D8, 44, C6, 09, 3A, B9, 72, F0, FF, 50, 84, D2, 69, D3, B5, 97, 1A, 6F, 0F, AF, F3, C6, C7, A7, 2D, 9F, 06, 00, 00...
 
[+]

Entropy:
7.9890  (probably packed)

Code size:
65 KB (66,560 bytes)

The file hdplayersetupit.exe has been seen being distributed by the following URL.

Remove hdplayersetupit.exe - Powered by Reason Core Security