vlc-setup-win8.exe

Soft

Delta Mode (New Media Holdings Ltd.)

The application vlc-setup-win8.exe, “Soft Setup ” by Delta Mode (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Software Program   (signed by Delta Mode (New Media Holdings Ltd.))

Product:
Soft

Description:
Soft Setup

Version:
4.7.1.1

MD5:
ca0e5c3f812aaddcfc4ca643aafaddad

SHA-1:
b1736bfd29ff2f5b228ccb19a045c4f9a7592910

SHA-256:
782161ac6611be83fe5312572ec61e5aaead13facc2f1e1669669eb6d7dd358e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 6:52:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.3.20.4

File size:
972.7 KB (996,032 bytes)

Product version:
5.5.1

Copyright:
Internet Soft Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\vlc-setup-win8.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/10/2015 11:41:11 AM

Valid to:
9/10/2016 11:41:11 AM

Subject:
CN=Delta Mode (New Media Holdings Ltd.), O=Delta Mode (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FC05E7F190060BBB1C537AEB499B4E03

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:1Q2pIvtO1zDtLApmWJUnExDqY82xBcDbCsEd8LTq/kDGCD+0zlEk8YJFvmq+wD3R:1Q2yVO1BAjU0+2xODbHh3qFqZmerN

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9160

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file vlc-setup-win8.exe has been seen being distributed by the following URL.

Remove vlc-setup-win8.exe - Powered by Reason Core Security