adobe_flash_player.exe

OOO Kod-Intertainment

The application adobe_flash_player.exe by OOO Kod-Intertainment has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from upnowtime.whenupdateswork.online.
Publisher:
Astalavista  (signed by OOO Kod-Intertainment)

Description:
Download Manager

Version:
1.3.2.1

MD5:
9c2461024395e8c907f2db6de01e5cb5

SHA-1:
4d4dbc342672ffb1716a4a85e297f2066fc27afa

SHA-256:
ce7969dcd4e9a75e91ba49848bf6ba3659673338fc5c21dd482e0f75c7ed09cf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 8:25:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.15.15

File size:
110.2 KB (112,800 bytes)

Product version:
1.3.2.1

Copyright:
Copyright © 2015

Original file name:
PreInstaller.NET.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe_flash_player.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/5/2016 5:30:00 AM

Valid to:
2/5/2017 5:29:59 AM

Subject:
CN=OOO Kod-Intertainment, O=OOO Kod-Intertainment, STREET="d. 9 str. 1 of. 36, Sukharevski M. per.", L=Moscow, S=Moscow, PostalCode=127051, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CC0E842B9BEC5B956C956FBCB6FC721B

File PE Metadata
Compilation timestamp:
3/28/2016 5:58:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

Entry address:
0x196BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9408

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
94 KB (96,256 bytes)

The file adobe_flash_player.exe has been seen being distributed by the following URL.

http://upnowtime.whenupdateswork.online/dl.php?ewvrv=f0vAVx_h5ODIPUcLUJVAK8ROMZQiAhhLIeAvZ_M9FJk.&cid=[CLICK_ID]&sid=[SUB_ID]&conversion_id=14596123059997&app_id=4&lp_id=1406&v=coin&stub_id=285&v_id=QAr_QGrETIvTy2RDqRG-A7vJJgKpCrfZb8-REk0Vwlg.&lpp=No match

Remove adobe_flash_player.exe - Powered by Reason Core Security