flashplayer_upgrade_30.exe

HDAudioCPL

Sapo

The application flashplayer_upgrade_30.exe by Sapo has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from cdnfiles.4shared.com and multiple other hosts.
Publisher:
VIA  (signed by Sapo)

Product:
HDAudioCPL

Description:
VIA HD Audio CPL

Version:
7.9.00.31

MD5:
f8911f7fd7410de922361405d79515c7

SHA-1:
7fadbe52764cf4f757e8ee056c4c2251768b9598

SHA-256:
51a4c5b74c6574ce3bc7b5c8384f63bd3f9de22e53228b6b05148180d25c017f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 5:03:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sapo (M)
16.4.27.18

File size:
273.4 KB (279,992 bytes)

Product version:
7.9.00.31

Copyright:
(c) <VIA>. All rights reserved.

Original file name:
HDAudioCPL.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flashplayer_upgrade_30.exe

Digital Signature
Signed by:

Authority:
Sapo

Valid from:
4/20/2016 11:32:40 AM

Valid to:
4/21/2017 11:32:40 AM

Subject:
CN=www.sapo.pt, O=Sapo, L=Bason, S=Bason, C=BE

Issuer:
CN=www.sapo.pt, O=Sapo, L=Bason, S=Bason, C=BE

Serial number:
00C32D02D923B044F0

File PE Metadata
Compilation timestamp:
4/25/2016 10:43:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:yz9SS8jdzkf3m/Eh26pDGmmCzy/AfcEio+oVGJykKD9u2wdAvwu01:yENbf6Z2t/lo+SxuNAvwuq

Entry address:
0x1304

Entry point:
68, A8, DA, 40, 00, E8, F0, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 45, B9, CA, 36, D6, 02, 26, 40, 92, B4, 7A, 00, 1C, 93, 26, 78, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 00, 00, 00, 00, 00, 00, 00, 00, D0, FF, 06, D0, D0, FF, 06, 00, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 03, 00, 00, 00, 3D, AE, 33, D9, 6B, 29, 38, 46, 9E, E3, 45, B1, 75, 33, F5, 4F, 01, 00, 00, 00, A0, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
228 KB (233,472 bytes)

The file flashplayer_upgrade_30.exe has been seen being distributed by the following 2 URLs.

Remove flashplayer_upgrade_30.exe - Powered by Reason Core Security