PlayLaterPatch.1.6.9.exe

PlayOn Patch Installer

MediaMall Technologies, Inc.

This is a self-extracting archive and installer. The file has been seen being downloaded from updates.playon.tv.
Publisher:
MediaMall Technologies, Inc.  (signed and verified)

Product:
PlayOn Patch Installer

Version:
1.6.9.9654

MD5:
e6ef184d1b68cc39ea3e3c13ed767674

SHA-1:
fea8ba161144fdf0239fd13077f4c2466a7cc69e

SHA-256:
66d70c0382f08103dea98ec411760faabbe653c83fa8e9034e9374f06fd18bca

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/25/2024 4:50:43 AM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.Blocker.dghxre
0.28.2.62671

File size:
15.5 MB (16,219,968 bytes)

Product version:
1.6.9.9654

Copyright:
© 2003-2014 MediaMall Technologies, Inc. All rights reservd.

Original file name:
PlayLaterPatch.1.6.9.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\playlaterpatch.1.6.9.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/14/2013 8:00:00 PM

Valid to:
11/14/2015 6:59:59 PM

Subject:
CN="MediaMall Technologies, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="MediaMall Technologies, Inc.", L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
23C02BCB0E08C77FB40D647B9DD27DC0

File PE Metadata
Compilation timestamp:
10/17/2014 10:08:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
393216:i/1rArCd5dyxVNaE606HRXIqCEPCsR6euGH5Pit4ukIjCfe6yQv7:i/1rArNTaBZi1EKsA6ZPPxIjCXv7

Entry address:
0xF31B0E

Entry point:
FF, 25, 1C, 1B, 33, 01, 00, 00, 00, 00, 00, 00, 00, 00, F0, 1A, F3, 00, 00, 00, 00, 00, 00, 00, 00, 00, D5, 22, 41, 54, 00, 00, 00, 00, 02, 00, 00, 00, 80, 00, 00, 00, 40, 1B, F3, 00, 40, FD, F2, 00, 52, 53, 44, 53, 60, 27, 4A, 4F, 77, 2C, C1, 4B, 84, B3, A1, F3, 1E, 4E, BD, F3, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 41, 64, 6D, 69, 6E, 69, 73, 74, 72, 61, 74, 6F, 72, 5C, 62, 61, 6D, 62, 6F, 6F, 2D, 68, 6F, 6D, 65, 5C, 78, 6D, 6C, 2D, 64, 61, 74, 61, 5C, 62, 75, 69, 6C, 64, 2D, 64, 69, 72, 5C...
 
[+]

Entropy:
7.9548  (probably packed)

Code size:
15.2 MB (15,924,224 bytes)

The file PlayLaterPatch.1.6.9.exe has been seen being distributed by the following URL.

Scan PlayLaterPatch.1.6.9.exe - Powered by Reason Core Security