flvplayer-chrome.exe

VASSANA KONGSOONGNERN

This is the setup program for CoolMirage, a potentially unwanted program (PUP) that display ads on the computer. The application flvplayer-chrome.exe by VASSANA KONGSOONGNERN has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. The file has been seen being downloaded from www.flvplayer-download.com and multiple other hosts.
Publisher:
VASSANA KONGSOONGNERN  (signed and verified)

MD5:
8899b5ad3406d899565478793e77e471

SHA-1:
32c2155acf58aa63510dc973cdb25f80909e0d7c

SHA-256:
25f17a80ea9920d0c99817af0244114e842aa2c82f661a874e419d7b0729c6ea

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
11/24/2024 10:10:16 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/CrossRider
2015.02.04

AVG
Generic
2016.0.3208

Baidu Antivirus
Hacktool.Win32.TornTV
4.0.3.1524

Dr.Web
Adware.Yontoo.54
9.0.1.035

ESET NOD32
NSIS/TrojanDropper.Agent.CB
9.11122

G Data
NSIS.Application.Adload
15.2.25

K7 AntiVirus
Adware
13.193.14857

Kaspersky
not-a-virus:Downloader.Win32.TornTV
14.0.0.2537

McAfee
Artemis!E5BC53DD0865
5600.6864

Reason Heuristics
PUP.CoolMirage
15.2.4.12

Sophos
CoolMirage
4.98

Trend Micro House Call
Suspici.EDD0D2A5
7.2.35

VIPRE Antivirus
CoolMirage Ltd
37248

File size:
128.7 KB (131,808 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\flvplayer-chrome.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/5/2014 5:00:00 PM

Valid to:
10/6/2015 4:59:59 PM

Subject:
CN=VASSANA KONGSOONGNERN, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Phuket, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7E630B1125BFC2AAB3F8750B7348F18B

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:uLk395hYXJi1jMGn3Gm6E6Ckm7T6Z1RnFd:uQqOow3Gm6EV/+Rnj

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6291

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file flvplayer-chrome.exe has been seen being distributed by the following 50 URLs.

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wVFVH4RAH36IPJTHG4INB396

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wRG4MC0D7OL2TKTHGNPI639O

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w6BKVAQFVHJ0IFUH0HBLOTO4

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wH98M1K2KLF3JKUH02R4LKDC

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wJTSD7QFRSCN6ETH03IOL35E

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w134JIKQ2FOCQGUH05S3Q480

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wR8TR26NV61NDQTHGUHIKVKM

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wPSF81P916P35MTH0E474J2I

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w9SMQ6AVND3R1NUHGVBVD14S

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wS0IVMMHMVOI8JTH0BEDBUM6

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wSO3NG15PEPNGL7GG9VNFQ68

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wP3E6KESJMIFTHTH0UFD3M7Q

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wGKKFMGIODQHBDTHGS7SA5CK

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w323KGCA447UEIUHGV41ME96

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wHS3P4BPJ9Q4NQTH0495PC6C

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wN2F78KU9MSUUSTHGBI2H60G

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wJ2MIB5DPTA44V6HGC0NU37A

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wNHJGID8DED8SDTHG9TCO046

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w0JT37OBTUL6VOTH0SRG31E8

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w7J0E7I1FDVA7STH02FQG68Q

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w51NP13NDAMAA9UH06QUS2FO

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wP2AD68P9RDGS0UHGC6M0C6I

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w8SRLBRK3BQ0JJUHG3LP104M

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w79LM1HKSGJQVTTH03J9OCFO

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wLCMJSD8QG0H0AUH05VJ8S3C

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w0EKB156TSC4MLTH03VA33EM

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=w75PQO5DBEBUUQUHG4PBK5EU

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wE2RBE6SOL2VMFUH0S7U29N0

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wQ5B22OJQSOQCFUH0LMU6H2C

http://www.flvplayer-download.com/.../mar9.php?subid=marmarlk&sid=wGS8FNGEJHI9RBUH08EBRKB8

Latest 30 of 114 download URLs

Remove flvplayer-chrome.exe - Powered by Reason Core Security