mediaplayerplus.exe

Mogoma

Delivery Superb (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application mediaplayerplus.exe, “Mogoma Setup ” by Delivery Superb (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Delivery Superb (Fried Cookie Ltd.)  (signed and verified)

Product:
Mogoma

Description:
Mogoma Setup

MD5:
6370b0b7695082d84618fd8cf76f9324

SHA-1:
b05551058bbbb3772bb7255ab4fac5e0234f64e7

SHA-256:
452032b9458f6f3a4957db624d32672b3fecd9e5fcb694120204c04d0de3d904

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 6:49:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.4.12.20

File size:
1000.3 KB (1,024,344 bytes)

Product version:
1.0.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mediaplayerplus.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 4:59:53 AM

Valid to:
6/22/2016 8:54:14 AM

Subject:
CN=Delivery Superb (Fried Cookie Ltd.), O=Delivery Superb (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211DDE033C8F24FD358ED7B6271AD4DE2B

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:QtN5kYBhSX+SJ4zswkgL6O4WPZBTz1xrsvPOIQnL:QbLhSJ4IwkeZ4WP3TfmmIe

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9289

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file mediaplayerplus.exe has been seen being distributed by the following 39 URLs.

http://www.downloadclearbest.com/c?x=ot9icDlJWvj5FmD7o6K 9Q3J6isoWtc68E19WWPU KI=&c=zVfr e9Vp05Yh3WetmwE3foLg9wwgeVnIu 3rMwzfqLg1ZuTENeYvZ7YzZ1mI/Qh9T5VektvUlDY3J ORIrYCSqgwqG5fz2MNq3QISx5QOaoxpHMtnYebqsRcZ/H1l3w PsOy54nHTSIateHCYwoqga7GjJ8iKUQYGQnpKe/rEg=&e=0&downloadAs=MediaPlayerPlus.exe&fallback_url=http://softdownload3.com/s4m/.../mediaplayerplus.exe

http://www.downloadclearbest.com/c?x=yNILq5T19Jk2bYIRdXORLlu8491EAVcmvJfYw9S/9gQ=&c=hPCT9RNKG12vZgWkC8od iM6U226nQE L3cRLO6tbM3B/F0tYGhEd8tfafk/o4JLUo8MT4OvweD5y0QtTdddhCEgwIKF8ebUwbxZztsMQFY7LS0xNpNYf4eYRMttwHtSwzyeQnQ4I mcQzpDYRSw5kQt E3mPn8BwktuSFQh5Xw=&e=0&downloadAs=MediaPlayerPlus.exe&fallback_url=http://softdownload3.com/s4m/.../mediaplayerplus.exe

http://www.contentsigntowers.com/c?x=hntrrAA1YMG84Aev602I7JAsBZhHbohKHNeu2XRB2Vo=&c=ruBzrcgq933pYrKYJUs1kwGdyElvRjD4QZXF2/VEZKbFDUbKdml0s5LAxkL6RZR2PZYZqOajMxiCKrFJ9Nlvj9gZV2B8OC35vVeyQ1AZxuOi4N37nzAuFKtHa46niu6qrdd50nPi/rD0PBwm vwp313pETLtH/W 38a/RSVE tA=&e=0&downloadAs=MediaPlayerPlus.exe&fallback_url=http://softdownload3.com/s4m/.../mediaplayerplus.exe

http://www.downloadclearbest.com/c?x=EwMtRlZKvpywkOyWqdy25UEa 0WMHsd9ArXPm/hlCnI=&c=6nIQ7kY qinpXIzLwADDkXZX9izd6Y9ddjmwpDB3SUKOuqLlsdCsm/fNejOS4i2fj8T 9FVFkfC6kkyvoEGpKLmzpufC1NySlfr4FJYeBvuxYP3i2DnovhtEEx6fj9q /ep48uJd/wrW0fuPr7qnHRz3EjOL tKNR7jugjfx6jY=&e=0&downloadAs=MediaPlayerPlus.exe&fallback_url=http://softdownload3.com/s4m/.../mediaplayerplus.exe

Latest 30 of 39 download URLs

Remove mediaplayerplus.exe - Powered by Reason Core Security