flashplayer__4369_i1327558306_il18.exe

KOMPANIYA КRЕАТА LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application flashplayer__4369_i1327558306_il18.exe by KOMPANIYA КRЕАТА has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.file-gate.net and multiple other hosts.
Publisher:
KOMPANIYA КRЕАТА LLC  (signed and verified)

Version:
1.1.6.20

MD5:
c20d838df811a510b83864070009031e

SHA-1:
98876dad30a2a085c9fe721df9bfdb7eea5110de

SHA-256:
f5f38e9a8656ad514126f2f009679aaa25c7c8780c595d3df4497832908c94d6

Scanner detections:
18 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/23/2024 10:43:57 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetize
2014.10.02

Avira AntiVirus
ADWARE/Adware.Gen
7.11.176.8

AVG
Downloader.Generic14
2015.0.3333

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.14103

Comodo Security
ApplicUnwnt
19673

Dr.Web
Adware.Downware.8564
9.0.1.0276

ESET NOD32
Win32/Amonetize.BR (variant)
8.10495

IKARUS anti.virus
AdWare.Amonetize
t3scan.1.7.8.0

Malwarebytes
PUP.Optional.Amonetize
v2014.10.03.11

McAfee
RDN/Generic PUP.x!cn3
5600.6989

NANO AntiVirus
Riskware.Win32.Amonetize.dffaha
0.28.2.62440

Panda Antivirus
Trj/Genetic.gen
14.10.03.11

Reason Heuristics
PUP.Installer.KOMPANIYAR.c
14.10.3.10

Sophos
Generic PUA JI
4.98

Vba32 AntiVirus
AdWare.Amonetize
3.12.26.3

VIPRE Antivirus
Amonetize
33584

Zillya! Antivirus
Adware.Amonetize.Win32.1260
2.0.0.1939

File size:
404.2 KB (413,920 bytes)

Product version:
1.1.6.20

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flashplayer__4369_i1327558306_il18.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/15/2014 8:00:00 PM

Valid to:
6/16/2015 7:59:59 PM

Subject:
CN=KOMPANIYA КRЕАТА LLC, O=KOMPANIYA КRЕАТА LLC, L=Kharkiv, S=Kharkiv, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
04CA5D77531C0E61E4DE2CB0E6E4B5B2

File PE Metadata
Compilation timestamp:
9/10/2014 10:59:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:dMqp6ikqgRpxhRKxlUNxLgzXq1A/IE8mRDv:dMqN6hRzXYXtmmRDv

Entry address:
0x17610

Entry point:
E8, 8B, 84, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, A9, 7D, 00, 00, 6A, 1E, E8, F3, 7B, 00, 00, 68, FF, 00, 00, 00, E8, C3, F4, FF, FF, 59, 59, 8B, 45, 08, 85, C0, 75, 01, 40, 50, 6A, 00, FF, 35, 94, AF, 3C, 00, FF, 15, 60, 21, 3C, 00, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, 5F, 7D, 00, 00, 6A, 1E, E8, A9, 7B, 00, 00, 68, FF, 00, 00, 00, E8, 79, F4, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3...
 
[+]

Entropy:
7.2784

Code size:
192.5 KB (197,120 bytes)

The file flashplayer__4369_i1327558306_il18.exe has been seen being distributed by the following 2 URLs.

http://www.file-gate.net/script/alldd.html?myref=www.newhdplugin.org&version=1.1.6.20&prefix=FlashPlayerSetup&campid=4369&instid[appname]=FlashPlayer&instid[appsetupurl]=https://launchpad.net/lightspark/trunk/lightspark-0.5.3/ download/Lightspark-0.5.3-win32.exe&instid[appimageurl]=http://www.tsxnrey.com/i/White Smoke Inc/.../150x150_v1Logo.jpg&prefix=FlashPlayer&ti1=MzIxM3w1MDY1fFJPfDN8MXx8|0508bd5422e63360d703a307569c5540|159efa00-40c6-11e4-a15f-0025b320a860&capp=FlashPlayer&AMt=1411217926349&AMh=7fn2b4gxIWmb09igS84d2Ie2zMXUjQgM3KAUfCzDKPbVydo5QZMSwcespsmVBC1AtdCH3iBb48loOaw3

Remove flashplayer__4369_i1327558306_il18.exe - Powered by Reason Core Security