hdvideoplayer.exe

The application hdvideoplayer.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from gf3.geo.gfsrv.net.
MD5:
515d1933f6e1ffacd3bcdf1c5b3e48c5

SHA-1:
1cd79386453dfd9e0c4c1e6fd2a8a4d61da778fd

SHA-256:
878905123da9a4c33510aa834f7992ba2dc465f3871b7216fb01ffe9d727f45b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/24/2024 7:48:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.4.7.21

File size:
2 MB (2,147,620 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\hdvideoplayer.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:eVFPulfnTU/BO/0hclyq2b4wauVRgULRXo2+/YXjUq8q:S6Aqnp2bNVW/YXoqZ

Entry point:
00, 00, 00, 20, 66, 74, 79, 70, 69, 73, 6F, 6D, 00, 00, 02, 00, 69, 73, 6F, 6D, 69, 73, 6F, 32, 61, 76, 63, 31, 6D, 70, 34, 31, 00, 00, 00, 08, 66, 72, 65, 65, 00, 20, BC, CA, 6D, 64, 61, 74, 00, 00, 03, 04, 06, 05, FF, FF, FF, 00, DC, 45, E9, BD, E6, D9, 48, B7, 96, 2C, D8, 20, D9, 23, EE, EF, 78, 32, 36, 34, 20, 2D, 20, 63, 6F, 72, 65, 20, 31, 33, 35, 20, 72, 32, 33, 34, 35, 20, 2D, 20, 48, 2E, 32, 36, 34, 2F, 4D, 50, 45, 47, 2D, 34, 20, 41, 56, 43, 20, 63, 6F, 64, 65, 63, 20, 2D, 20, 43, 6F, 70, 79, 6C...
 
[+]

Entropy:
7.9996  (probably packed)

The file hdvideoplayer.exe has been seen being distributed by the following URL.

Remove hdvideoplayer.exe - Powered by Reason Core Security