flash_player_setup.exe

flash setup

Digital Zones

The application flash_player_setup.exe by Digital Zones has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from workingupdate.nowinstallupgrade.online and multiple other hosts.
Publisher:
Digital Zones  (signed and verified)

Product:
flash setup

Version:
1.0.0.0

MD5:
bee48898dd1925d3a3ff7af646c39a3d

SHA-1:
c000b259897ab7f5b7bc536529ce086c12f7a97e

SHA-256:
279160af966e40271c4fdca6fd526d7eea073617da9546514038753c28cf8e54

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/1/2024 9:27:15 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/TrojanDownloader.Adload.AZ trojan
8.0.319.0

Norman
Gen:Variant.MSILPerseus.30942
02.04.2016 17:35:19

Reason Heuristics
PUP.DigitalZ.Installer (M)
16.5.28.22

File size:
116.9 KB (119,752 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
Flash.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/28/2016 2:00:00 AM

Valid to:
3/29/2017 1:59:59 AM

Subject:
CN=Digital Zones, OU=Digital Zone, O=Digital Zones, STREET="ul. Akademika Koroleva, d. 9 korp. 5", L=Moscow, S=Moscow, PostalCode=129515, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
07775D7C7B8C20E915DD534EA4F8DB84

File PE Metadata
Compilation timestamp:
5/10/2016 8:57:29 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:G82s/N+UiHznlGjyaiAXXmLb8Db3zTBuMZAn6FS6nri:G8/FyTnlWyaiAXXmLbmbPMMZ+6FS6

Entry address:
0xC21E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
41 KB (41,984 bytes)

The file flash_player_setup.exe has been seen being distributed by the following 25 URLs.

http://workingupdate.nowinstallupgrade.online/dl.php?gther=L8Qvh1T1ybclQwAJiWpKlFbQ_ZrSjNjvMrKdzF1G2Sg.&cid=P23P13R4630745592665297116&sub=4177&conversion_id=14630745604986&app_id=4&lp_id=1661&v=tribat&stub_id=305&v_id=7HPUglQEdb9odUFb9x16XodTLjYw-kET5v8SWXa-b-U.&lpp=*-*-*

http://newtest4pc.ready4newsoft.tech/dl.php?dfrtge=PpwRkWz5LyxtL_vGPv-alkpi1qSU4ug9lzqrJ5NdKB8.&cid=us3tmkggfs54ecad8fbw&subid=3829&conversion_id=14630710050235&app_id=4&lp_id=1401&v=tribat&stub_id=305&v_id=BZ2CDzZ-I0AA-Xk2M0bMvQtdSHKJ_6tseDn7BSj4M9g.&lpp=*-*-*

http://getupdate.softupdate4free.xyz/dl.php?vytre=mwK9xqzoV7CJFZFuMzUljhhSqRfSzOS0OjpXu8EpXWQ.&cid=MTA1MXw1MjEyfENBfDN8MXx8Y3pKeipTbFJETVRNM05WOU9kMHhFVVVkSk9IZFVMVkJqTkVKQ1dFZHlVR0pFfHw&conversion_id=14630878521395&app_id=4&lp_id=1602&v=tribat&stub_id=305&v_id=5NH5Je0282gXtEuvWVZpCGNqa6xvloov38lc69NHWLQ.&lpp=*-*-*

http://installupgradenow.alwaysfreeupdate.xyz/dl.php?vtge=Ng4WtNxhGPEQZdqC1dWAshWscO8dCXLx14dzm1z-R-E.&cid=177093849644&sid=465554&conversion_id=14631040633439&app_id=4&lp_id=1609&v=tribat&stub_id=305&v_id=b1eHFbNj24MW9BEjJzx-loh9y_yA-JtaqsmVBMi4gpA.&lpp=*-*-*

http://readynewsoft.noteupgrade.online/dl.php?gyte=CLewqHlWIIChBaR_iGisoxGg9pB7VpPKRIflToz1LAU.&subid=VjJ8MTgxOHwyODQ3MzV8NTcyMzJ8MTQ2MzExNTA0MXxhMzZmMjc5OS00OWM1LTRkNTEtY2Q3Mi03NzdhMmRkNTk5ZDZ8NjguMzcuMTI5LjQ1fHw0fDlhMWI0ZjI2M2Q2N2Q4ZThlM2E4NmZiMTg1OWQ2ZjAy&conversion_id=14631153028239&app_id=4&lp_id=1401&v=tribat&stub_id=305&v_id=9zGkKgiq_2Oil5RtvqyzdcbfnxHmLHB-_WglPOShuM4.&lpp=No match

http://app4com.ready4maintain.top/dl.php?fgsh=UhtopDfT-Qw1wd0I9sitpTYHGuohmSBqFaltbtgBkBI.&cid=JFC1802_NY.rYawzqp-Pc6zBXJnPb6&conversion_id=14631010773035&app_id=4&lp_id=1543&v=tribat&stub_id=305&v_id=52oJI41vW5RsquYTHNnZF1E9bY_2ZXJmTRhtrU-bq7s.&lpp=*-*-*

http://getupdate.softupdate4free.xyz/dl.php?vytre=Iu5sv4NYl_zlgN93nmUm2GAAg-MzAOgMZUlagyP7ABQ.&cid=MTA1MHw1MjA1fEJSfDN8MXx8Y3pKeipTa1ZJTVRFME5WOUhSVnBIWDFST1drSTRMVkJrUWxSQ1dGRm9TRXhSfHw&conversion_id=14630864920040&app_id=4&lp_id=1617&v=tribat&stub_id=305&v_id=hQ03Y_kWB2Ai5G456XE-L5hKd689g1CytMeDhjl1a-4.&lpp=*-*-*

Remove flash_player_setup.exe - Powered by Reason Core Security