adobe_flash_setup.exe

CoinisRevShare Downloader

OOO PREM''ER-SERVIS

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application adobe_flash_setup.exe by OOO PREM''ER-SERVIS has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the ProfitServis Downloader installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from maintainupgrade.vidupdate.org.
Publisher:
CoinisRevShare  (signed by OOO PREM''ER-SERVIS)

Product:
CoinisRevShare Downloader

Version:
1.0.5.a0.1_34625

MD5:
69adba6c0ef640e2443e89edc2d87501

SHA-1:
19086cab3ab07bc93ef7f9982c1a4ecb62189bae

SHA-256:
bada307c7330f61d2ab3d2b3050d8862d2da847d4e2c11368edf296b67463e60

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 7:24:00 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallCore.Gen9
3.6.1.96

avast!
Rootkit-gen [Rtk]
2014.9-160101

AVG
Generic
2017.0.2877

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.InstallCore.KG
21776

Dr.Web
Trojan.InstallCore.56
9.0.1.01

ESET NOD32
Win32/InstallCore.WC potentially unwanted application
10.7.0.302.0

K7 AntiVirus
Trojan
13.202.15609

Malwarebytes
v2016.01.01.03

NANO AntiVirus
Riskware.Win32.InstallCore.dotkie
0.30.16.1110

Reason Heuristics
PUP.ProfitServis.OOOPREMERSERVIS.Bundler (M)
16.1.1.15

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Threat.4150696
38882

File size:
801.7 KB (820,944 bytes)

Product version:
1.0.5.a0.1_34625

Copyright:
CoinisRevShare

File type:
Executable application (Win32 EXE)

Bundler/Installer:
ProfitServis Downloader (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe_flash_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/14/2015 7:00:00 PM

Valid to:
1/15/2016 6:59:59 PM

Subject:
CN=OOO PREM''ER-SERVIS, O=OOO PREM''ER-SERVIS, STREET=Chelyuskinskaya 11, L=Moscow, S=Moscow, PostalCode=129336, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A2577095E8662DFB2C04C6E76F38E411

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:a0Mvp3aOMzxqPR9a42Tz+KHjkzC0GkYROKxso7VR9pr+OrcYPbtqVTJ7F8nac:aXv0OMzxg9P2Dk25lh7793rcYP0TNFNc

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.6698

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file adobe_flash_setup.exe has been seen being distributed by the following URL.

Remove adobe_flash_setup.exe - Powered by Reason Core Security