vlc-setup.exe

Application Generic

Download Beta (Alpha Criteria Ltd)

The application vlc-setup.exe, “Application Generic Setup ” by Download Beta (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Installer Generic   (signed by Download Beta (Alpha Criteria Ltd))

Product:
Application Generic

Description:
Application Generic Setup

Version:
5.0.3.2

MD5:
4b18beb93570943cfed254df2e365af2

SHA-1:
6f817cc4a3a377b71aa8f7411709da1fd98cc8a2

SHA-256:
881a21b65e7173f86a444c4817d600ae11182d187817a80c52a4f2f7a0d63c93

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/5/2024 5:51:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Installer.Installer (M)
16.1.29.1

File size:
978.4 KB (1,001,832 bytes)

Product version:
4.1

Copyright:
Software Internet Generic

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\vlc-setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 1:50:13 PM

Valid to:
7/27/2016 3:53:04 PM

Subject:
CN=Download Beta (Alpha Criteria Ltd), O=Download Beta (Alpha Criteria Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B4B4166A3B4A9E9EFB16280151B2BE36

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:5OWp6xYrVBbgDt7Y5Ih4VrzU5aromIvP83TSb8nT21m/Bx:5jExWbg5YOknUM2383mb8T2s5x

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vlc-setup.exe has been seen being distributed by the following URL.

Remove vlc-setup.exe - Powered by Reason Core Security