NIX Player

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: November 9, 2023
Last Seen: April 29, 2026
OS(es) Affected: Windows

The NIX Player software from http://x5.erasedrnlcziu.download/262028/1739/zk3z552/gmw3ks9/8436# is promoted to Web surfers as an update to the Adobe Flash Player from Adobe System Inc. They may be suggested that the NIX Player software allows them to render 1080p videos, stream in Firefox, Chrome and Internet Explorer, as well as benefit from security improvements and a compatibility mode. However, the NIX Player is not a product of Adobe System Inc., and it is not published by legitimate developers. The NIX Player is deemed as a Potentially Unwanted Program (PUP) that might load advertisements from unreliable publishers on your screen. We found that the NIX Player is promoted through pages registered to the 162.255.119.242 IP address including:

broadsistematictoupdate[.]bid
erasedrnlcziu[.]download
getyourealiableupdtnownofeethisweek[.]stream
newsteadysystemtoupdating[.]trade
readyteamtoupdate[.]stream
softsfreeandgreatupdatesloadthismonth[.]bid
theofferservicestableforsystem[.]review
theonlinegoodsitecontentsafeall[.]win

Web surfers may experience pop-up windows that feature the following text associated with the NIX Player:

'NIX Video Player (Recommended)
Please Install NIX Video Player (Recommended)
Watch video in full 1080i HD
Faster playback and streaming in Firefox, Chrome and Internet Explorer
Safe and secure.
Compatible with all popular filetypes, AVI, MOV, MP4, MPG, WMW & more
Installing takes under a minute, and you do not need to restart after installation
DOWNLOAD'

Computer security experts warn that the NIX Player software may use misleading information, logos from trusted sites and fake user reviews to convince users to install riskware. We have received complaints from users suggesting that the NIX Player is used by third parties to redirect Web traffic to questionable online stores. Computer users who might have installed the NIX Player recently are likely to notice pop-under windows that feature promotional materials and limited time offers. Installing the NIX Player software does not appear to boost the capabilities of browsers like Google Chrome, Internet Explorer, Mozilla Firefox and Opera. You might want to remove the NIX Player and related browser cookies with the help of a trustworthy anti-spyware scanner.

Analysis Report

General information

Family Name: Trojan.MSILZilla.FB
Signature status: No Signature

Known Samples

MD5: b5f01de57ce347091d975a18be18a7aa
SHA1: 934c0d4d13d4bbfa52fa5605c36b594b17be14a9
SHA256: 0E92EEF958E071091809216D9ABB84403D1A9F4035A8FABB9D5C3D729A67D00A
File Size: 5.63 KB, 5632 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description ConsoleApp6
File Version 1.0.0.0
Internal Name ConsoleApp6.exe
Legal Copyright Copyright © 2021
Original Filename ConsoleApp6.exe
Product Name ConsoleApp6
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 1
Potentially Malicious Blocks: 1
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSILZilla.FB

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • ReadProcessMemory
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...