kmpaddedcode_oppercd.exe

Ebooks Media

The application kmpaddedcode_oppercd.exe by Ebooks Media has been detected as a potentially unwanted program by 13 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files4.downloadmanager149.com and multiple other hosts.
Publisher:
Ebooks Media  (signed and verified)

Product:
eBooks Media

Version:
81.5.6.8830

MD5:
fe8d848069c79d366389fc31c392d768

SHA-1:
246955027528b6ba38b756e2c65bf397b1f5f5ac

SHA-256:
bb7b6c1042f2d7426271aa51a835289ad56b5c2a1e87a75c1bfcb41abb78d159

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
11/5/2024 2:19:25 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Win32:PUP-gen [PUP]
2014.9-151108

Baidu Antivirus
PUA.Win32.DownloadAdmin
4.0.3.15118

Bitdefender
Gen:Variant.Application.Bundler.DownloadAdmin.4
1.0.20.1560

Bkav FE
W32.HfsAdware
1.3.0.7383

Dr.Web
Trojan.Vittalia.884
9.0.1.0312

ESET NOD32
Win32/DownloadAdmin.P potentially unwanted (variant)
9.12532

F-Secure
Gen:Variant.Application.Bundler
11.2015-08-11_1

G Data
Gen:Variant.Application.Bundler.DownloadAdmin
15.11.25

MicroWorld eScan
Gen:Variant.Application.Bundler.DownloadAdmin.4
16.0.0.936

Reason Heuristics
PUP.DownloadAdmin.EbooksMedia.Installer (M)
15.11.8.10

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151106

VIPRE Antivirus
Trojan.Win32.Generic
45076

File size:
868.8 KB (889,656 bytes)

Product version:
81.5.6.8830

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\kmpaddedcode_oppercd.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/2/2015 11:01:38 PM

Valid to:
9/6/2016 2:41:42 PM

Subject:
CN=Ebooks Media, O=Ebooks Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
6986F899668DE1FC

File PE Metadata
Compilation timestamp:
11/17/2014 6:04:46 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ERgljRK87UwDRaDwewZyy+R8sHMTZeJq6TbEdKrVU:pRK87UwtacewAyYMT4qsFr2

Entry address:
0x4601

Entry point:
E8, FA, 92, 00, 00, E9, FE, 8B, 00, 00, CC, CC, CC, CC, CC, 55, 8B, EC, 83, E4, C0, 83, EC, 34, 53, 56, 57, E8, 2F, 12, 00, 00, 8B, F0, A3, 10, 45, 41, 00, 85, F6, 75, 15, 68, F0, 42, 41, 00, E8, FA, DA, FF, FF, 83, C4, 04, 6A, 37, FF, 15, 58, F0, 40, 00, 68, 00, 01, 00, 00, 6A, 00, 56, E8, 02, 11, 00, 00, 56, E8, EC, 0F, 00, 00, 8B, 5D, 08, 6A, 00, 53, 56, E8, 90, 11, 00, 00, 33, FF, 83, C4, 1C, 89, 7C, 24, 3C, 85, DB, 7E, 34, 8D, 49, 00, DB, 44, 24, 3C, 83, EC, 08, DD, 1C, 24, 56, E8, 10, 11, 00, 00, 8B...
 
[+]

Entropy:
7.9690  (probably packed)

Code size:
52.5 KB (53,760 bytes)

The file kmpaddedcode_oppercd.exe has been seen being distributed by the following 9 URLs.

http://files4.downloadmanager149.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=ID&cb=1789956770&osName=unknown&browserName=unknown&zTmp=1&executable=1197159

http://files4.downloadmanager149.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=TH&cb=-157589352&osName=unknown&browserName=unknown&zTmp=1&executable=1197159

http://files4.downloadmanager149.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=DZ&cb=-979567090&osName=unknown&browserName=unknown&zTmp=1&executable=1197159

Remove kmpaddedcode_oppercd.exe - Powered by Reason Core Security