adobe_flash_setup.exe

Installer

OOO KOD 7

The application adobe_flash_setup.exe by OOO KOD 7 has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from prepared.softterminal.download. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OOO KOD 7  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
d1ff79823f15e88d109435cef527055b

SHA-1:
b0cb0caf317c0278e8507651d052e98ba46c552b

SHA-256:
47724552c00c1d5531fdaddde4720a8241cbdc227b51af3a8f095fd272b096a4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 4:47:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.OOOKOD7.Installer (M)
16.5.10.12

File size:
788.6 KB (807,552 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\adobe_flash_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/4/2015 5:00:00 PM

Valid to:
5/4/2016 4:59:59 PM

Subject:
CN=OOO KOD 7, O=OOO KOD 7, STREET="per. Kotelnicheski 1-i, d. 3 korp. 1", L=Moscow, S=Moscow, PostalCode=109240, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DA768041E424621AF314DB7899002F9

File PE Metadata
Compilation timestamp:
4/13/2016 1:17:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:AzKYQr202LgvEZpU1LLh6UbJyvvBHvSWCwqhkIijPrxw8DClgDllTHmxIJ+qcOKa:sfQr202LSqSV3JyvvBHvSWCwqhkIixz

Entry address:
0xC32EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3825

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
773 KB (791,552 bytes)

The file adobe_flash_setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove adobe_flash_setup.exe - Powered by Reason Core Security