hdvideoplayer_1862410849.exe

Nesino

Secure Software Products

The application hdvideoplayer_1862410849.exe, “Nesino Setup ” by Secure Software Products has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.headmetavault.com.
Publisher:
Secure Software Products  (signed and verified)

Product:
Nesino

Description:
Nesino Setup

Version:
1.7.3.5

MD5:
c19593349b106cfa56b34959452d1fdc

SHA-1:
2f5f8a545060a2561341dd1fc8cf69414d3b0235

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/23/2024 3:10:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.16.4

File size:
948.4 KB (971,144 bytes)

Product version:
2.5

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\hdvideoplayer_1862410849.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/20/2016 2:59:38 AM

Valid to:
4/20/2017 2:59:38 AM

Subject:
CN=Secure Software Products, O=Secure Software Products, L=Las Vegas, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
5E7095902F2C0288

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9361

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file hdvideoplayer_1862410849.exe has been seen being distributed by the following URL.

http://www.headmetavault.com/nftN1MDoA_fXgM_ZQ5ziiRietfs u3gzNbkNjLdIQy46 vzeKAPzaXEM TYOzNIXUGuRLNSDaWCnq7P98As2 6ygVZ6Ld4lvcTwXUpyxAAKF8FT9W6ZJ0dnlOW_9KbjN2ZA95LbYdHfry6uL4bm3IdVm5rYRGuefrodACW90IB34 LcDThTlwuEq2sGUQOvWYV8amwz11X3akX9_Is5AzCDgHywriw3Xwn_XQzpUU6u6s 41PMQTY_os_NlWC1XlyRYYmucGM6srsoFtQZB8ju4LfD67HuS230F6VqVHvrzr0POqOLtZhWgJRpQjaVCT_yNnTQY8ffp0bqU5eUuUsHohZ2D8_aLXZtzw_V_1lg8n41_U3a8O_H_b2OKHhxnth1PliWv1obDPGQEeBQQ0bTehJgK01hwnT_66iubX8a_c6ZvPFoz0O45rbRI7kpYl58vi9DW7Rde2mGXOdTVLmmbqUlG3ajg uJz843WzmJJybZbRWKgLUNF4SNyJdaktMavDvE2a2k8_Uv11J3tCAJGSbT9cH_irZNb2vMlmV9UZ86g0pAmvVYYh 1Ola_GM46vsrL2rhgymezddJuInWTfB M3UhkPtGfmkzupauI2bVLMKUlp0JfTFWgWigDq5 R2VZzEBWxcoU2Y8ghCfxQ4pj aOQXaMnsJrliFEi4mTkeYQV i5cEG6ZOaCkmuUnL8ev TlIwlAwajF4N96fceQtbr9MoYaZ9hAEgncGZ6PxOECWzNf_l7RGabQS_wKgSl5hIbnRqhujZ DjwbqOZ4IvipznO4iW5761LGQ4377p4XFk0XrOalDT7_U71AblFK0D2i-Gy4AAEQ3F5slGeyny9EFwR_D5eddCCcCLSS3DuTGa74Jz DR685Mk8IaPXTgdNGPAg==

Remove hdvideoplayer_1862410849.exe - Powered by Reason Core Security