flashplayer.exe

Fileangels

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application flashplayer.exe, “Premium Installer ” by Fileangels has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. The installer is marketed through download protals and search ads as the free Adobe Flash Player but will also install additional software offers which include adware, PUPs and browser toolbars. The file has been seen being downloaded from 3acwn.trackvoluum.com.
Publisher:
Premium Installer   (signed by Fileangels)

Product:
Premium Installer

Description:
Premium Installer

Version:
2.4.8.1

MD5:
c242f714a38eec7be94280004ec5d698

SHA-1:
c98ceac4778c79ad9ebcac4e9f43faa15b2feaf9

SHA-256:
2d3125eb5001d1fdac12740ee21365ad985c5860b502e7966c9ba3e8c698dcb6

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/25/2024 1:05:05 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OptimumInstaller
2014.11.05

Avira AntiVirus
ADWARE/iBryte.Gen4
7.11.183.48

AVG
Adware AdPlugin.BOV
2014.0.4189

Clam AntiVirus
Win.Adware.Ibryte-5789
0.98/19588

Comodo Security
Application.Win32.IBryte.BO
19996

Dr.Web
Trojan.DownLoader11.38739
9.0.1.05190

ESET NOD32
Win32/Adware.iBryte.BO (variant)
8.10671

Fortinet FortiGate
W32/Zbot.AAN!tr
11/4/2014

F-Prot
W32/A-71902d70
v6.4.7.1.166

G Data
Win32.Adware.IBryte
14.11.24

K7 AntiVirus
Adware
13.185.13888

Kaspersky
not-a-virus:AdWare.Win32.iBryte
15.0.0.494

Malwarebytes
PUP.Optional.OptimunInstaller
v2014.11.04.10

McAfee
IBryte-FRT
5600.6956

NANO AntiVirus
Riskware.Win32.IBryte.dhbrit
0.28.6.62995

Reason Heuristics
PUP.Installer.Fileangels.L
14.11.4.21

Sophos
iBryte Premium Installer
4.98

VIPRE Antivirus
Threat.4778314
34232

Zillya! Antivirus
Adware.iBryte.Win32.3434
2.0.0.1975

File size:
69.4 KB (71,024 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) Premium Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flashplayer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/13/2014 4:00:00 PM

Valid to:
7/14/2015 3:59:59 PM

Subject:
CN=Fileangels, O=Fileangels, STREET=4600 Madison Ave FL 10, L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1D54F646CB5A85211464AF0FDAB3D591

File PE Metadata
Compilation timestamp:
10/25/2014 9:00:25 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:oPAjHc3lHlJYgdzLhEU/VOSs54cOaahZU9cszJwyo8vv:oPAjFgdzLhR/VO1OFhtZY3

Entry address:
0x447B

Entry point:
E8, 48, 05, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, 20, 61, 40, 00, FF, 25, 24, 61, 40, 00, CC, CC, 68, ED, 44, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 1C, B0, 40, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C...
 
[+]

Entropy:
5.7098

Code size:
16.5 KB (16,896 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security