uplayermediaplayer-setup.exe

Groovecom

The application uplayermediaplayer-setup.exe by Groovecom has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files5.safelink9.com and multiple other hosts.
Publisher:
Groovecom  (signed and verified)

MD5:
80dc1dea16388aa72427c939d4124ab7

SHA-1:
aa216dffcf2dc133ba45f69636efe6aa3ec9f4d3

SHA-256:
b04e8a724f79d17d3215b5e4284fb879f3e6c724595f2771a91fe82bc022a115

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
11/24/2024 7:32:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.I
508

Bitdefender
Application.Bundler.I
1.0.20.1285

Dr.Web
Adware.Downware.2220
9.0.1.0257

ESET NOD32
Win32/DownloadAdmin
9.9723

G Data
Application.Bundler
15.9.24

herdProtect (fuzzy)
2015.11.8.10

MicroWorld eScan
Application.Bundler.I
16.0.0.771

NANO AntiVirus
Trojan.Win32.Downware.crgjbr
0.28.0.59492

Reason Heuristics
PUP.DownloadAdmin.Groovecom.Installer (M)
15.9.14.16

Sophos
Download Admin
4.98

VIPRE Antivirus
DownloadAdmin
28602

File size:
610 KB (624,664 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\uplayermediaplayer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2014 1:00:00 AM

Valid to:
2/26/2017 12:59:59 AM

Subject:
CN=Groovecom, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Groovecom, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C8ED38817030CF19BE6EE39708627BA

File PE Metadata
Compilation timestamp:
6/22/2012 8:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:XrdiMybLCUVSG+u46LDu/eoABSafzNsZGwELv:X+bLcG+Ivu9ABrLWZpUv

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file uplayermediaplayer-setup.exe has been seen being distributed by the following 2 URLs.

Remove uplayermediaplayer-setup.exe - Powered by Reason Core Security