adobe_flash_player-6879370.exe

Downtown Media

The application adobe_flash_player-6879370.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from intva31.procedureconnect.info and multiple other hosts.
Publisher:
Downtown Media

Product:
Downtown Media

Version:
25.9.6.4853

MD5:
2af85599a26401e47479fdcf94578420

SHA-1:
6479df693a2a28cb4a6f008cb311ed6810660cc1

SHA-256:
d7db5d3e8c3d36dc801f2ed094729b826e188f920184bae5b850687964dea0cd

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/14/2024 3:17:34 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.Kazy.128374
11.5.0.6191

ESET NOD32
Win32/DownloadAdmin.Q potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.DownloadAdmin (M)
16.4.15.17

File size:
884.3 KB (905,504 bytes)

Product version:
25.9.6.4853

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\adobe_flash_player-6879370.exe

File PE Metadata
Compilation timestamp:
3/8/2015 4:21:52 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:1chWwjQY+ET7kjkp6gXIPsOrtVs2gf+KJGx:KhP7QFtVsL

Entry address:
0x1686

Entry point:
E8, 15, CB, 00, 00, E9, 1F, C4, 00, 00, FF, 25, C4, 97, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 81, EC, 18, 01, 00, 00, B9, 05, 01, 00, 00, 8D, 44, 24, 10, 90, C6, 00, 00, 40, 83, E9, 01, 75, F7, 55, 56, 57, 8D, 44, 24, 1C, 50, 68, 04, 01, 00, 00, FF, 15, B8, F0, 40, 00, 8B, 2D, 04, F2, 40, 00, C7, 44, 24, 0C, 08, 00, 00, 00, 8D, 9B, 00, 00, 00, 00, 33, F6, 83, FE, 08, 7D, 1D, FF, D5, 33, D2, F7, 35, 70, 94, 48, 00, 8B, 0D, 6C, 94, 48, 00, 46, 83, FE, 08, 8A, 14, 0A, 88, 54, 34, 0F, 7C, E3, C6, 44...
 
[+]

Entropy:
7.9670  (probably packed)

Code size:
56 KB (57,344 bytes)

The file adobe_flash_player-6879370.exe has been seen being distributed by the following 3 URLs.

Remove adobe_flash_player-6879370.exe - Powered by Reason Core Security