flashvideoplayer.exe

Del

Safe Installer Company

The application flashvideoplayer.exe, “Del Setup ” by Safe Installer Company has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.worldhostingchuckle.com.
Publisher:
Kehage   (signed by Safe Installer Company)

Product:
Del

Description:
Del Setup

MD5:
f473b48baf1bfb02edf35cef5c048d50

SHA-1:
572c840184caf71ce3273135598d8b48aee3c03e

SHA-256:
cc39baf24d6e438bf6f268b09d9c02aa4682714d12690419343444d30cb9e6dd

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 9:49:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.16.10

File size:
950.8 KB (973,576 bytes)

Product version:
1.4.3

Copyright:
Fast App wizard

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\flashvideoplayer.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/3/2016 4:12:38 AM

Valid to:
3/22/2017 3:38:38 AM

Subject:
CN=Safe Installer Company, O=Safe Installer Company, L=Las Vegas, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
6C5CD790DC645C41

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9326

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file flashvideoplayer.exe has been seen being distributed by the following URL.

http://www.worldhostingchuckle.com/4YNbyyWFusSz6ab_3GApG7X5twnOEC_aJg2XC1NzHD1Sa4n6w7sLSRgoQw5heJwcGRm1X61GL5SWDKNp2xPS4oUFIE iHD_3tYME9rJBkd8WmWyXppinVYjkXgyFGmbroWgmQzOF42V5977ELXOakChUk s0_B5Pp4mcPDE47f0msOx8rjD zod3gSIFphL3CyhjG8V3AkGDAkbn7x9ZTBrIG91gWDq20InsUxfhRbfHrC4AqvoHFiwjP1eVeWNuCFHg2BhF0BjUfTGyRuPyXLPV 2HlKP1Om84S7sbufdLQ75zzYinI0eJb2OTlLeTEN9OGjy0wZJ1bIRP v3jLDs eyT no7H3D6rjah80_HS_oiQf1rurzCZ7koJ17djFm ArS6cLhmQFba SAzeNAsuVKeFg qE37RBqElryQRFZq_JjMsCQFw4_6DrqExj viW3t1w6Ra8wsNYmFORwTwf285JzucUGfm2TftL3BYF9UKukotRSFUpu1yGt4mQA6X4nDRhkchRtjRmjgs_C6jIP3e HT2TphFFmqHK8PO4wiZbL1UjFHZSlJbl1N1W8UZC4IA9tYmUr YIbzbsPuBXhSttHboXrBHvbyl_sjB_PXZoJCIGJmcYQKXvXRBFrKN3JAvlDl6LicXH E65pI1nDc OMQjXGcnNj3xaahcBP_38j0k2znpgn0h0eWb5Ot8V7o_O4XUtxWgpHEAwEy3YpT4JUIR0vvbxJ1SGPGXGx7vFCwsC81sOuhZr4MM89OgOLgtGvwYd 4QQ5thFFliF438m9lvfwqgR2wXNxKJMp3wsNq2lW6qso27rZYiFP4Af3jLQEm3wV4n5eV1JK5APs5Z4y 3BAsF24Qhjk3 LQ4yYbBk=-GzYAAOSbnp_ndDz6JRQlKfYMNuDAoZ9owAFo2Bg7XwuaeY2r1pCJaPMHj9hgyQaXf5j83sDPAQ==

Remove flashvideoplayer.exe - Powered by Reason Core Security