adobe_flash_setup-130613469.exe

CertFreeCertificateContext

Bicoastal Interactive

The application adobe_flash_setup-130613469.exe by Bicoastal Interactive has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from intva31.clearviewmedia.info and multiple other hosts.
Publisher:
Bicoastal Interactive  (signed and verified)

Product:
CertFreeCertificateContext

Version:
9.14.157.518

MD5:
b008de0cee65b46311c3f10c46949ac5

SHA-1:
f6b415855aae1ad265d09d9bef87e815d889ae17

SHA-256:
dab242cf6c9d8fcaf13ad85e6295f2d8b0648bd055bb0c57e6e75169e683e74f

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 2:43:49 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.1729

Comodo Security
Application.Win32.DownloadAdmin.Y
26568

Dr.Web
Trojan.Siggen7.10262
9.0.1.040

Emsisoft Anti-Malware
Application.AdLoad
8.17.02.09.05

IKARUS anti.virus
PUA.DownloadAdmin.Aa
0.1.3.4

Qihoo 360 Security
HEUR/QVM10.1.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
PUP.DownloadAdmin (M)
17.2.9.17

Vba32 AntiVirus
Signed-Downware.DownloadAdmin
3.12.26.4

File size:
139.8 KB (143,144 bytes)

Product version:
7.12.96.910

Copyright:
Copyright (C) 2014 Default Browserpos

Original file name:
Taskbar.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\adobe_flash_setup-130613469.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/19/2016 10:50:40 PM

Valid to:
5/19/2017 10:50:40 PM

Subject:
CN=Bicoastal Interactive, O=Bicoastal Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0096C56AE03C38A570

File PE Metadata
Compilation timestamp:
11/29/2016 6:25:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x79BD

Entry point:
E8, BC, 36, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, EC, C4, 41, 00, FF, 15, D0, 50, 41, 00, 85, C0, 75, 18, 56, E8, 0E, 10, 00, 00, 8B, F0, FF, 15, BC, 50, 41, 00, 50, E8, 13, 10, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, CC, B8, 41, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, C3, 3D, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 8D, 85, E4, FC, FF, FF, 6A, 4C, 6A, 00, 50, E8, B7, 3D, 00, 00, 8D, 85, E0, FC...
 
[+]

Code size:
77.5 KB (79,360 bytes)

The file adobe_flash_setup-130613469.exe has been seen being distributed by the following 3 URLs.

http://intva31.clearviewmedia.info/dl-pure/1205333/.../?bc=1205333&checksum=130625344&ephemeral=1&filename=adobe_flash_setup.exe&cb=-441067318&hashstring=589ca5b5a47f3&usefilename=true&executableroutePath=1205085&stub=true

http://intva31.clearviewmedia.info/dl-pure/1205333/.../?bc=1205333&checksum=130698406&ephemeral=1&filename=adobe_flash_setup.exe&cb=-1727306114&hashstring=589ca5b5a47f3&usefilename=true&executableroutePath=1205085&stub=true

http://intva31.clearviewmedia.info/dl-pure/1205333/.../?bc=1205333&checksum=130633394&ephemeral=1&filename=adobe_flash_setup.exe&cb=-1619816082&hashstring=589ca5b5a47f3&usefilename=true&executableroutePath=1205085&stub=true

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-6-18-250.compute-1.amazonaws.com  (52.6.18.250:80)

TCP (HTTP):
Connects to a104-96-90-194.deploy.static.akamaitechnologies.com  (104.96.90.194:80)

TCP (HTTP):
Connects to net-inst-ash.opera.com  (37.228.108.239:80)

TCP (HTTP):
Connects to static.vnpt.vn  (113.171.234.110:80)

TCP (HTTP):
Connects to host-213.158.175.73.tedata.net  (213.158.175.73:80)

TCP (HTTP):
Connects to a95-100-170-32.deploy.akamaitechnologies.com  (95.100.170.32:80)

TCP (HTTP):
Connects to host88-rangeA-akamai-aanp.cdn.enlcs.isp.sky.com  (2.127.246.88:80)

TCP (HTTP):
Connects to host80-range3-akamai-aanp.thlon.skybroadband.com  (90.223.204.80:80)

TCP (HTTP):
Connects to host-213.158.175.90.tedata.net  (213.158.175.90:80)

TCP (HTTP):
Connects to a95-100-170-26.deploy.akamaitechnologies.com  (95.100.170.26:80)

TCP (HTTP):
Connects to a104-96-90-192.deploy.static.akamaitechnologies.com  (104.96.90.192:80)

Remove adobe_flash_setup-130613469.exe - Powered by Reason Core Security