player.exe

hosts

The executable player.exe has been detected as malware by 6 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.papyon.co.
Product:
hosts

Version:
1.0.0.0

MD5:
9d85c061443ed258da389d2a99d44fea

SHA-1:
dd2bd87deffb3a386a3ac4f2b07a5b06e5d10e34

SHA-256:
59e33c586b01a50fe665bde0d27f54613c250f2907dbcb9e9cd9a4d287cdf9e2

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/26/2024 5:11:26 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160215-2

Dr.Web
Trojan.StartPage1.757
9.0.1.05190

ESET NOD32
MSIL/StartPage.AT trojan
8.0.319.0

F-Secure
Variant.Kazy.390954
5.15.21

VIPRE Antivirus
Threat.4150696
47432

File size:
120 KB (122,880 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
hosts.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\player.exe

File PE Metadata
Compilation timestamp:
2/17/2014 6:09:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:Wdt3cwDfP8cy4iXfW9uoOxce4wp70XOkZRWTZfMgxihzt7nE9wGZ+:0cwDcjDXOTuKc9k7zIhZ+

Entry address:
0x108BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
58.5 KB (59,904 bytes)

The file player.exe has been seen being distributed by the following URL.

Remove player.exe - Powered by Reason Core Security