adobe_flash_player.exe

Astalavista

The application adobe_flash_player.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from updatenew.update-groups.net.
Publisher:
Astalavista

Description:
Download Manager

Version:
1.1.7.1

MD5:
e4d48685b953361f5d760798a4ae164b

SHA-1:
f5e02695c53b74fdd350c48b5c5aa247a5b0a480

SHA-256:
329c3a58792d772d9fc49fedc53b483226cb9f8514339e8e2546de71a6abc004

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 9:55:52 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.InstallCore.1556
9.0.1.05190

Reason Heuristics
PUP.Bundler.Astalavista.Meta (M)
16.2.2.11

File size:
46.2 KB (47,296 bytes)

Product version:
1.1.7.1

Copyright:
Copyright © 2015

Original file name:
PreInstaller.NET.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe_flash_player.exe

File PE Metadata
Compilation timestamp:
1/31/2016 5:15:42 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:QKcWFHPFM/5MjHbvn2C9jbhzQ4c2OwzYcHeofk+MrTYNSJ:isPFCWL2C9HhQ5vNoM3rTCSJ

Entry address:
0x965E

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
30 KB (30,720 bytes)

The file adobe_flash_player.exe has been seen being distributed by the following URL.

Remove adobe_flash_player.exe - Powered by Reason Core Security