mediaplayer_update.exe

safe StORe BTW

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application mediaplayer_update.exe by safe StORe BTW has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The file has been seen being downloaded from download.file8desktop.com.
Publisher:
RFXGI  (signed by safe StORe BTW)

Product:
RFXGI

Version:
9318.15828.1345.2711

MD5:
c2e8573c0752df6e9ad47652e6cb9838

SHA-1:
12f7b096260d433e9dd876c87fdb79efc0d64195

SHA-256:
bd01bd615a17ce29d48c7255a1a66003106c8a8d767410708c9da51dc5509b8c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 2:12:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
17.1.26.7

File size:
588.1 KB (602,232 bytes)

Product version:
9318.15828.1345.2711

Copyright:
RFXGI

Trademarks:
RFXGI

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mediaplayer_update.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/30/2015 5:30:00 AM

Valid to:
1/28/2016 5:29:59 AM

Subject:
CN=safe StORe BTW, O=safe StORe BTW, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6108717788D723A1E9FEAD5857BE1D1E

File PE Metadata
Compilation timestamp:
12/6/2009 4:22:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9788

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file mediaplayer_update.exe has been seen being distributed by the following URL.

http://download.file8desktop.com/1440754402/1440754402/1440754402?93584807231XmJvLjI3cDYwLzgoMiFcOSo5LTYwJWM6LTAzLDIfbDowHW1tZ2BtY21sXmxcOj9nc2ZsaF9hJCktSFlqWWdecCNjKDorHk81UktxVFdYNG0 Q3I2c2FqS2tiX0ZJTUtzRi9PWEZEL3BHVEkyPjAtaFVvNGlXPDBBZS0zUm4 TUtJS2lCJ2FuT2JMVlhkUVVtQjRcMTtiaGpKdElzPHFkZTM9cUA0K1c8a0RJRW1uUSxLRDNRTHBOK0tRNWRwUm5KWnkpQWBqLDU8LzU8VGlQX1gqSUloZkR1XE12REI0aGRMLnZNYV5nX2BCQmRGelNKLlVBcmVrcy5iXUsuSl5IdUw/YXJrYTRILl5GcEk/.../T0wsWi1OTmYwZlpncE90aDBlODBAXzEyQGwsM1FtPVFTZC1rQ1xdSm1hUW1hMWlocCtjWWRRLmBBcEk6c0pVQFxeZz9ubHFQX0hsZmw8cEZuO3JeXitDZERDMTcxSjNCMF5eTkFOaEQvTy9cVytXNXBxX1JDQXFXaVwtXXE9X2VrSy9IZWlOdG5wVmdYQWFLVkFhb0lrYHFCMmJDKk5mcVRsTW51QWZKb3FQL01oay5vUyg5T2BPbUF1TSpmUWxYQzRSZUc L2FHTl1qanQ9PlFQQCVyUV1hZkxHcjpncjhQbzJkPFRiO2A5RkZTNklnUm1KS3FMTWFtRmY2UEtBYkhTYVJ2QHFTR3VQRD5kajBgSEBHSkVlSUZlRi1RWjFbPURoZFd4LXVUZFIvSmAwMVBdVWhOT012Zk9iNktLQzw W08tQ0pPWTAtcGtoNmhsYXJcTjJwLFxsRlJjaydvPkNfUHVjP3FvXGtiV0kqSi81QEVRTWYvcUtoPEhOL15DUWwpOkg8ZmV

Remove mediaplayer_update.exe - Powered by Reason Core Security