mediaplayersetup.exe

Fere

Amazing Software Products

The application mediaplayersetup.exe, “Fere Setup ” by Amazing Software Products has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.bestbundletoday.com.
Publisher:
Amazing Software Products  (signed and verified)

Product:
Fere

Description:
Fere Setup

Version:
3.5.2.1

MD5:
9e40a85e84b579e3fd0fc3dda66da59b

SHA-1:
11f5d57b889eb8495a16dd2ee70bfc47a8d1f35d

SHA-256:
0a3e57fc62a21b1df395a49dea65aff0052a0e3f26c4ef10f0f796eb80917bae

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/23/2024 7:19:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.16.3

File size:
954.5 KB (977,448 bytes)

Product version:
3.0

Copyright:
File

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mediaplayersetup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/21/2016 2:55:38 AM

Valid to:
4/21/2017 2:55:38 AM

Subject:
CN=Amazing Software Products, O=Amazing Software Products, L=Las Vegas, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00B3238F64F3F894B9

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9336

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file mediaplayersetup.exe has been seen being distributed by the following URL.

http://www.bestbundletoday.com/c?x=vRJ/p28/iU3axHO 0wWuCyi3yLYcIvhAp6L44utANiY=&c=x9NRxxyIOZ5Hf8OUXVWP9DJMJqrXHy7SUstvZV4BTGQf Cj0d9/Ahqm2WOseMNxBbPbyN1eklHgOW 4OigrYw7vIevuGlVOjOTBafVFOe02xKtEPfiY8fdvS3nsMypkV&fallback_url=http://.../Flash_Player_Setup.zip&downloadAs=MediaPlayerSetup.exe

Remove mediaplayersetup.exe - Powered by Reason Core Security