player setup.exe

The executable player setup.exe has been detected as malware by 1 anti-virus scanner. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from clkdeals.com.
MD5:
451f705306f976d3312669206b6264a8

SHA-1:
1f23023c7c11f47a5569512d4b67faa64a6bebfd

SHA-256:
7df7679fe490be1b822e59c382da4a7feacc1e69fb6be2e0469f797196475ca3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/25/2024 3:33:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win16.Generic
16.7.5.0

File size:
990.5 KB (1,014,264 bytes)

File type:
Executable application (Win16 EXE)

Common path:
C:\users\{user}\downloads\player setup.exe

File PE Metadata
Compilation timestamp:
11/27/2014 11:53:42 AM

OS version:
5.0

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:VLMoaD1TpxI7HKczk5998wdvwbVmwybcWKsLUh:m1TpOa599tvuToKwUh

Entry address:
0x118D6

Entry point:
B8, 90, 92, 57, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 67, 64, 61, 73, 64, 66, 74, 72, 68, 34, 00, 35, 15, 53, 25, 40, E9, 92, 3C, E3, E0, 33, 79, 1D, 25, 39, CA, 5E, FB, 4C, FA, 82, 61, CE, 80, E0, 3C, 9C, 42, B8, B1, C7, C6, 18, B0, 62, 59, AB, 53, 83, 4D, 14, E1, D2, 66, A7, CF, E4, EE, 42, 0F, 66, 65, 4F, E9, 91, 35, C4, B7, C4, D1, 5B, 20, B9, 1C, C5, D4, 0B, B3, BA, 9E, C0, FC, E2, F2, 4D, 4C, F0, ED, 3B, A6, 81, CB, 83, 8E, F4, BB, AE, AF, 5C, CF, 11, 3B, 65...
 
[+]

Entropy:
7.9793  (probably packed)

Code size:
155 KB (158,720 bytes)

The file player setup.exe has been seen being distributed by the following URL.

Remove player setup.exe - Powered by Reason Core Security