azdefs.exe

Arizona Bet Slip Definition Files

Data Solutions

The application azdefs.exe by Data Solutions has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from lottopro.ddns.net.
Publisher:
Data Solutions   (signed by Data Solutions)

Product:
Arizona Bet Slip Definition Files

MD5:
ac8a33580dcd6b6103106ee3c11a1d8b

SHA-1:
ab3c24b25551c15cdc0d460c31762e5a0f0de306

SHA-256:
9fc0d23979e4fd9d51a892cb4927721eea4628b2d82cdc44cdc718e4bd8d9b06

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/8/2024 7:59:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.12.18

File size:
306.2 KB (313,560 bytes)

Product version:
1

Copyright:
(c) Data Solutions 2015

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\azdefs.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/13/2015 6:00:00 PM

Valid to:
2/5/2016 6:00:00 AM

Subject:
CN=Data Solutions, O=Data Solutions, L=Polk City, S=Florida, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
050DCF11EA3840E80017604CD51D5DFA

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:4/QiQXkKEuIXFvQ4BHfnZmSuJCYUOSqNxVA8KKISXEVTdcC4ezy0l7RCqS+:gQi9KchjBHfnZ99YUOSAyGXqTdcC4b49

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8657

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file azdefs.exe has been seen being distributed by the following URL.

http://lottopro.ddns.net/.../azdefs.exe

Remove azdefs.exe - Powered by Reason Core Security