mediaplayerlite-0540.exe

Kemulaf

Beta Setup (Alpha Criteria Ltd.)

The application mediaplayerlite-0540.exe, “Kemulaf Setup ” by Beta Setup (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.packagerepositorypackage.com and multiple other hosts.
Publisher:
Beta Setup (Alpha Criteria Ltd.)  (signed and verified)

Product:
Kemulaf

Description:
Kemulaf Setup

Version:
4.0.5.5

MD5:
b0659a2cb295d4b382be5366017b40d5

SHA-1:
c68e8e9000ff510cbe5fc5b780ffc1bb992f76b3

SHA-256:
5e08b694d6f64f6c20993095140e13518cd4bcc994d516405417c98537043075

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/27/2024 7:30:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.7.7.13

File size:
947.1 KB (969,864 bytes)

Product version:
4.0.4

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\mediaplayerlite-0540.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 1:05:12 PM

Valid to:
7/27/2016 6:04:14 PM

Subject:
CN=Beta Setup (Alpha Criteria Ltd.), O=Beta Setup (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121DBA9CC399DC1BEE2669DA6FF3ACD5A4E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:imiYVeWr1yz9xU1DVoYer+Fk6xcJ4MkdvuICc:i3CUhx8mYC+FnxbdvuIn

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9324

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file mediaplayerlite-0540.exe has been seen being distributed by the following 34 URLs.

http://www.packagerepositorypackage.com/c?x=8STu1EyrB1rextyMmshucHUxDRqrwCYmm3IgB0B528U=&c=n57/luTulWFtW03uD1ROtJ ehQZf4zVkdtYnMG8Qi/cT2PcHNK6piY bmlqxheYzV4L5q3OHy1UJ6tYherV6nEl5gmgGnlOFE3ppj5O7uArMLtblLSEZC20SZ3EcBSBjSH89icJSTHAkJo8QmcpduhnGtQIbP7DHexmUXvhjH4o=&e=0&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=y4dP0wbwBPrWs51cmRO2lws7hshFUfpmlsw4kIIp6HU=&e=0&c=Wj7DzLYVYYl7KlftRLaEZI1eL5R92hknOWDmO5gb1U BPGeiRf1XiIyZ79FKOP98DIasmEuUSinFHiGpGB9gfcUI0OJ0BkrZ94mUh/0zAgDhqFn4eA3EoxIKMGzVS64Xoqfjdv4OeMrunYFrabCkZONOZyx0A7Rzj87JA5CXeO4=&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=dKpES8ls4WdUkDZ828faaULqoFnOksnsKCrANhwAqcE=&c=WGkkZDl5L4y4YEfuMMbpdhtTFJM7rHbIarDgVZHADCBuAZ95/is 6VWe5sPiHT716tDGiAFfNTXYj4xuILrIskpJWKDena1tEnZgoM4DCYy1tRhWCKacV8ue8g9edQKgZsIgsAGlst9Yv4yFrxf 3jmwy/1H1MaMcIGq81wbGes=&e=0&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=TRJ3PjALC9TKd43xDuCcenUgRBEU2B0mIvSV0DBK8UY=&c=rEdnUq/e3pMBcM1A8MO7g2No7za3hisu6I HCxJN6aps92M0VUcINopf5Lx6E4A5pTmMwNZR ENfAYw/XsgEw6Yf4Ajwz/n652peTfRNoId8XtTiO7d5Z21c3KYriavorJyv SEb7 FkrIHH9f/uwMxzqL47vWGMlOQij/MuNv4=&e=0&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=m66zVjcBA/VfYGPhEvqpUqQEN4IKCcGrDpfm9OoZN0s=&e=0&c=pbc4jF/x6iWaS4b4wRahUW/UhPqQXBsmYn0MFZydSl5YXuY9CKwC5yQpwZADJN8tq9cZV/5t9uzNYOu/1ztS0QCNF3ShArgR1UBU 4dW5u81aWYBbqZ EbnBsH7seWTBdtCQA OWyT192pAKWxkRJfILEssw5A16OPtvJpA/7eU=&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=s7nuTyiOMm8bcABmcDSTYgORsc0IBVsbjcQYIHGrOeI=&e=0&c=ibCwiHocMtwSRjigoJSiVWSJ4AaQSYONtnLr5OpJoDbK2fMu k6jaU6jMOcPa5DBUVmLWfpcCneTiOsgVzso9ju/YdwecbP6Hw4C5EX/UWb396Md48 TprZlRB4hTCftMf8eEuchXPLnjzAFWLMkBndaHLZyIilr4CvgtoZPdDc=&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=8nyENliMhbXo35sEZo8VQaj Oz1BMYGWoh0kwjgL4e0=&c=z20b2BAxjJAEsjqi/ImzER8yaG9VKQF76XwPgyNBlUr60w58LHC6Y6iPX3dLPybGAT KqO3e8ZdzL2LrxuVLevMB/IxpH87T6zmiZGUtwGBogAfEr4NdKxNrsi2PKpHz3uJHq 96phBgpzDiu1tKQRK5aLMtfxiSC7BGhICQGo0=&e=0&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=Kh3lHhQ5BvuheKcB3VBh6oradzDxYUXisddb3j6MEnU=&e=0&c=hJz1RMurBznXRHtGDdJXe4xuw838VzZuM1hgF0M0t5Y4AnMTO66O60uUCTq5djYP5CyQI9bTuZ1KPFxoc8MJ2Mu3H6VagZ9ibwWL8Txw GxGTyf2ATATTSZKyA0mfYeOF4YyUQ5gTwAnzK JqW1pB1FKsG0xXS /Haqx9DBjFk=&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=SO8Ev5sbM3hDEk6zr6SeJEvkeFB8B9p2l0RBNh6Jl A=&c=H5qSPKILwxLu 1G3vSywtq7g1rhwcvHCzljZg1YaTqlujXmRVvqya8MEw0gueNwZ 4TcNja9tPfG9r9tAKEC6aeBP6vanzAKxnAZ9ubQkAKPjScG6cQC3tPCAT1tCF58AgMbT/mZtEXcZ3z2P9HyY72yqtN5sUkf/TaboXJz O0=&e=0&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=gsoQFZxovfd5wvw5HuZVnHgDHQ1fFGOm5ngZg7wD hM=&e=0&c=npMz4JeRX2H0YdzNWABLPeMxn wG8x4Vks0ZYve16AfGrO1xKDIuATcLoMbTlz7R38mA 3yB2RdOydzXTCN6dzfEdCDLPLdpvVfQDeBfqyGgYOA0g P1 c6zMYU078K8FHQIw2cy8i8t2cBcxoR Z5U//aQTXwDNzhdN RlP3mI=&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

http://www.packagerepositorypackage.com/c?x=q/kahf1fbYgQx8XgsYYlc0jQ9nXBf d0QNi3LcYQCo8=&e=0&c=DNi31bKQuDuo02QHo/fhVcItxLEwJvLfoDH9ixDOSxMP0hpMcKMhjNKSo7igJICRCxOI5gYoazqgDux6S5jJzapUdpWTXYOgY Gyrsnx2yDXhV mbyFoiygxFmIdjJnmeupM8jgOcJzej86ITKxXeWah/1VzBeg6NLTyhx0h/ZI=&downloadAs=MediaPlayerLite-0540.exe&fallback_url=http://.../setup-mediaplayerlite-0.5.4.0-silent.exe

Latest 30 of 34 download URLs

Remove mediaplayerlite-0540.exe - Powered by Reason Core Security