adobe_flash_player-50346723-50346723.exe

Downtown Media

The application adobe_flash_player-50346723-50346723.exe by Downtown Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from intva13.buildwebmaster.info.
Publisher:
Downtown Media  (signed and verified)

Product:
Downtown Media

Version:
25.9.6.4853

MD5:
f628ce325ad5c2fd8c96bc40e259b099

SHA-1:
2fc2828d91b69a5e226d000ca4fdef1772292118

SHA-256:
07ce9e7803b2e4ca4d130b0e5ba4f3c9cfdce81e79070f5d680952df5ae1033d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 8:04:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vitallia.Downtown.Installer (M)
16.4.15.13

File size:
889.9 KB (911,288 bytes)

Product version:
25.9.6.4853

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\adobe_flash_player-50346723-50346723.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2016 10:14:39 PM

Valid to:
3/8/2017 10:14:39 PM

Subject:
CN=Downtown Media, O=Downtown Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00C86FE599444C83FF

File PE Metadata
Compilation timestamp:
4/7/2015 5:40:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:gDyVE4+VswWcAHE2vwFwUnPh3s89SRElfEHl1YmsjG4Dc9:64Ggk2vCwUnZ3szElsHg44o

Entry address:
0x2156

Entry point:
E8, 15, C1, 00, 00, E9, 17, BA, 00, 00, 83, EC, 78, 56, 57, E8, F6, F7, FF, FF, E8, 81, F2, FF, FF, 8B, B4, 24, 88, 00, 00, 00, 8B, BC, 24, 84, 00, 00, 00, 56, 57, E8, CC, 0F, 00, 00, 56, 57, E8, D5, FC, FF, FF, 8B, 06, 83, C4, 10, 50, FF, 15, B0, 00, 41, 00, 83, F8, FF, 74, 2E, 8B, 0E, 68, 3C, 1E, 4B, 00, 68, 30, 1D, 4B, 00, 68, 04, 01, 00, 00, 51, FF, 15, CC, 00, 41, 00, 85, C0, 74, 07, 3D, 04, 01, 00, 00, 76, 2A, 5F, B8, 3C, 00, 00, 00, 5E, 83, C4, 78, C3, 8B, 15, B8, 01, 41, 00, C6, 05, 33, 1E, 4B, 00...
 
[+]

Entropy:
7.9656  (probably packed)

Code size:
56.5 KB (57,856 bytes)

The file adobe_flash_player-50346723-50346723.exe has been seen being distributed by the following URL.

Remove adobe_flash_player-50346723-50346723.exe - Powered by Reason Core Security