adobe_flash_player.exe

Installer

OOO Digital

The application adobe_flash_player.exe by OOO Digital has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from getupdate.softcontinents.website. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OOO Digital  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
079869b52b71ab3fae665017abf3c7d4

SHA-1:
2bbd0e324325f3c84cadb0a25f80a725d8574df5

SHA-256:
39c1a6ab2c5b655c997f775a69304bd66021e6b55ee7eb04c62b3c07bb4866f0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 6:40:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.OOODigit.Installer (M)
16.6.8.10

File size:
787.6 KB (806,536 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe_flash_player.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/27/2016 4:00:00 PM

Valid to:
2/27/2017 3:59:59 PM

Subject:
CN=OOO Digital, O=OOO Digital, STREET="g. Moskva, ul. Lipetskaya, d. 24 korp. 2", L=Moscow, S=Moscow, PostalCode=115404, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
14F484F64BE4FEF77B16AEBC75033225

File PE Metadata
Compilation timestamp:
4/13/2016 1:17:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:7WnSvKuUAKKGDEVXb2nv7t1QlQd44LtvphkuF:7WjAKxYVavAe

Entry address:
0xC2F5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3901

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
772 KB (790,528 bytes)

The file adobe_flash_player.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove adobe_flash_player.exe - Powered by Reason Core Security