flashplayer.exe

MIDIA TECHNOLOGIES LLC

The application flashplayer.exe by MIDIA TECHNOLOGIES has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Midia Downloader installer. The installer is marketed through download protals and search ads as the free Adobe Flash Player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
MIDIA TECHNOLOGIES LLC  (signed and verified)

MD5:
2e785db93721b8a4cc4ef5e49ff400a9

SHA-1:
45e0aa8add939e1df73713f2c21e9ddbf1d8a7e3

SHA-256:
147242a7e165de3e0050119ccb269e0d3b28cd79a19c887df9f1afe14871779b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 2:02:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Midia Technologies (M)
16.10.2.17

File size:
633.4 KB (648,648 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader

Common path:
C:\users\{user}\downloads\flashplayer.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
8/21/2014 11:54:02 PM

Valid to:
4/11/2015 3:45:06 PM

Subject:
CN=MIDIA TECHNOLOGIES LLC, O=MIDIA TECHNOLOGIES LLC, L=Lewes, S=Delaware, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049B2C66393AA0

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:6bymMA2VwgLKcUkF0PH6M59UsmYWArCugo:5hZwgLDUzSMBTN0o

Entry address:
0x757CC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 84, 55, 47, 00, E8, 28, 08, F9, FF, A1, 7C, 7A, 47, 00, 8B, 00, E8, 0C, 2A, FE, FF, 8B, 0D, 14, 78, 47, 00, A1, 7C, 7A, 47, 00, 8B, 00, 8B, 15, 3C, 4D, 47, 00, E8, 0C, 2A, FE, FF, 8B, 0D, 74, 79, 47, 00, A1, 7C, 7A, 47, 00, 8B, 00, 8B, 15, 74, 47, 47, 00, E8, F4, 29, FE, FF, A1, 7C, 7A, 47, 00, 8B, 00, E8, 68, 2A, FE, FF, E8, DF, E5, F8, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
466.5 KB (477,696 bytes)

Remove flashplayer.exe - Powered by Reason Core Security