vlcmediaplayer-setup.exe

Tomorrow Software Installer

EBooks Media

The application vlcmediaplayer-setup.exe, “Tomorrow Software Installer ” by EBooks Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Tomorrow Software  (signed by EBooks Media)

Product:
Tomorrow Software Installer

Description:
Tomorrow Software Installer

Version:
2.0.0.1

MD5:
6cd4435ea00d8ff3a11a283649e953c8

SHA-1:
a9e07eeb1da499bab66b6e831c0455384be4b62f

SHA-256:
7a30e158fda459622d2c75a62065de3b15eed9267dd1d8ab4e45f286fa71d047

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/5/2024 10:55:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DownloadAdmin (M)
17.2.13.1

File size:
874.8 KB (895,776 bytes)

Product version:
2.0.0.1

Copyright:
Copyright (C) 2015

Original file name:
tomorrow-setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Common path:
C:\users\{user}\downloads\vlcmediaplayer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/5/2015 2:00:00 AM

Valid to:
2/6/2016 1:59:59 AM

Subject:
CN=EBooks Media, O=EBooks Media, L=san francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
54636717359CD60DB0B87873A4B7B2F9

File PE Metadata
Compilation timestamp:
6/26/2015 4:54:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xC7A2

Entry point:
E8, 3C, 05, 00, 00, E9, 57, FD, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, 4B, 41, 00, 89, 0D, 54, 4B, 41, 00, 89, 15, 50, 4B, 41, 00, 89, 1D, 4C, 4B, 41, 00, 89, 35, 48, 4B, 41, 00, 89, 3D, 44, 4B, 41, 00, 66, 8C, 15, 70, 4B, 41, 00, 66, 8C, 0D, 64, 4B, 41, 00, 66, 8C, 1D, 40, 4B, 41, 00, 66, 8C, 05, 3C...
 
[+]

Entropy:
7.9554  (probably packed)

Code size:
51.5 KB (52,736 bytes)

The file vlcmediaplayer-setup.exe has been seen being distributed by the following URL.

http://dl1.dlmirror6.com/dl?bc=1184287&pid=piratebay&country=IL&cb=-2100567054&signature_id=65&osName=Windows&osVersion=7&browserName=Chrome&browserVersion=38&zTmp=1&executable=1188607&variation=norefer

Remove vlcmediaplayer-setup.exe - Powered by Reason Core Security