adobe_flash_setup.exe

OOO

The application adobe_flash_setup.exe by OOO has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from soft67.net.
Publisher:
OOO   (signed and verified)

MD5:
be19a087cc449f0330ff80ae38db7680

SHA-1:
b6e4cc61a87f6633f5ef683be5525f9686475a4f

SHA-256:
575a58445ce90f343f30806342f612b75c4943e10bd1829bdf5cde3bb5e4c6ab

Scanner detections:
2 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 11:32:31 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.QL potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.Installer.OOO.R
14.10.1.14

File size:
828.1 KB (848,008 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Nezavisno od jezika

Common path:
C:\users\{user}\downloads\adobe_flash_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/29/2014 2:00:00 AM

Valid to:
9/30/2015 1:59:59 AM

Subject:
CN="OOO ""Finans Servis""", O="OOO ""Finans Servis""", STREET=proezd Serebryakova 6, L=Moscow, S=Moscow, PostalCode=129323, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E1FA7367E750C9DB1BC6472E5E6D59C7

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:LgvEGsMUJ2YXsHIuFFASHLwsWIpzJvhag3Ak49P:L8JTL0VuFFASrhPhO

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file adobe_flash_setup.exe has been seen being distributed by the following URL.

Remove adobe_flash_setup.exe - Powered by Reason Core Security