kmpaddedcode_oppercd.exe

Sundex

The application kmpaddedcode_oppercd.exe by Sundex has been detected as a potentially unwanted program by 14 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from files4.downloadmaster1.com and multiple other hosts.
Publisher:
Thin Supersonic Software Installer  (signed by Sundex)

Product:
Thin Supersonic Software Installer

Version:
90.7.3.526

MD5:
2151b66982af3d213df9fc9d28253936

SHA-1:
353f0cb6c73af73ef5f770072886cf11785ea102

SHA-256:
ef3f7496ca2e6762915da06529e445759c7f729ba952c064d959707f1f6b1b2b

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
11/24/2024 11:07:49 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.DownloadAdmin
2015.09.11

avast!
Win32:Malware-gen
2014.9-150911

AVG
Downloader.Generic_r
2016.0.2989

Baidu Antivirus
PUA.Win32.DownloadAdmin
4.0.3.15911

Dr.Web
Trojan.Vittalia.388
9.0.1.0254

ESET NOD32
Win32/DownloadAdmin.N potentially unwanted (variant)
9.12237

Fortinet FortiGate
W32/DownloadAdmin.K
9/11/2015

IKARUS anti.virus
PUA.DownloadAdmin
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.210.17188

McAfee
Artemis!2151B66982AF
5600.6645

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.15909

Sophos
Mal/Krap-K
4.98

Vba32 AntiVirus
SScope.Downware.DownloadAdmin
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
43668

File size:
758.6 KB (776,784 bytes)

Product version:
90.7.3.526

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\kmpaddedcode_oppercd.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/6/2015 7:47:39 AM

Valid to:
9/6/2016 4:47:46 AM

Subject:
CN=Sundex, O=Sundex, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00F0FF9C795F266C56

File PE Metadata
Compilation timestamp:
10/10/2014 3:57:14 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:7Ppailzxuz1SP27VC5qPXRWbGtEh3DiOdyqRYjM5m/xg17mp+JZdtojgMDEazNlX:7NASO5C5qvRWitW32OcKcM5m/xg1CwHk

Entry address:
0x1A33F0

Entry point:
60, BE, 00, 90, 4E, 00, 8D, BE, 00, 80, F1, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9038

Packer / compiler:
UPX 2.90LZMA

Code size:
748 KB (765,952 bytes)

The file kmpaddedcode_oppercd.exe has been seen being distributed by the following 50 URLs.

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=SA&cb=98567315&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=AE&cb=258139313&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=VN&cb=1014851338&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=VN&cb=1608017278&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=VN&cb=19376151&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=SD&cb=-928171256&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=BY&cb=1903064515&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=SA&cb=1010665300&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=NG&cb=1021158158&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=IN&cb=-339956568&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=VN&cb=-2041854476&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=SA&cb=-753581664&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=TH&cb=-200747170&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=ID&cb=-693565574&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=TH&cb=-621883584&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

Latest 30 of 67 download URLs

Remove kmpaddedcode_oppercd.exe - Powered by Reason Core Security