flvplayer-chrome.exe

VASSANA KONGSOONGNERN

This is the setup program for CoolMirage, a potentially unwanted program (PUP) that display ads on the computer. The application flvplayer-chrome.exe by VASSANA KONGSOONGNERN has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. The file has been seen being downloaded from www.flvxplayerdownloads.com and multiple other hosts.
Publisher:
VASSANA KONGSOONGNERN  (signed and verified)

MD5:
e09f5ab98efee8ac991017f013134054

SHA-1:
fb0e16bb9816942490b596e3eac43bc03c4fa531

SHA-256:
e9342d47fc15de524cee5f0e83cb048e31a0a29b8e2eacc2b180c21e1e3ca4df

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
11/24/2024 10:07:04 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dldr.Adload.76248
7.11.198.100

AVG
Generic
2015.0.3246

Baidu Antivirus
Adware.NSIS.Yontoo
4.0.3.141228

Dr.Web
Adware.Downware.8319
9.0.1.0362

ESET NOD32
NSIS/TrojanDownloader.Adload.AA
8.10936

G Data
NSIS.Application.Adload
14.12.24

K7 AntiVirus
Adware
13.188.14468

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo
14.0.0.2727

Reason Heuristics
PUP.VASSANAKONGSOONGNERN.Q
14.12.28.14

Sophos
CoolMirage
4.98

VIPRE Antivirus
CoolMirage Ltd
36160

File size:
74.5 KB (76,248 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\flvplayer-chrome.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/6/2014 1:00:00 AM

Valid to:
10/7/2015 12:59:59 AM

Subject:
CN=VASSANA KONGSOONGNERN, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Phuket, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7E630B1125BFC2AAB3F8750B7348F18B

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:HQpQ5EP0ijnRTXJD560qCzlTllqUnTenyI03AOsHc:HQIURTXJD57QUnhvATc

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.1862

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file flvplayer-chrome.exe has been seen being distributed by the following 50 URLs.

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wLK11Q9JVKU0F5AHG8M2IIAK

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wI2EHKDVUIQ269AH0CHV5BCE

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w6AE0P6F0U8HH2AH0M5CT5D2

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wK0LQ1P7H9NPB49H0SQJFN9A

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wAL06HECL3V6288HGAOHVC16

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w4H7TP00C1TJUC4HG233I56M

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w3D4D4A29DGQIS8HGLUPFQHC

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w0VSKOKK3JKG419HGQR3QB8U

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w992BSDISSDEA34HGK6EI5GQ

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w69HRV1SLPLLJ14HGHI7S74M

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wDMRA8TAJQESIL8H0T4S7R76

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wRLQQONEUDJT3U7HG6NKKB84

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wMGSI1GUKLG68S3H04Q20M0P

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wDE0BG6A443OV2AH0379VK1K

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wT4IVCUOESA2O34HGV6GJ4DG

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wTADBDHN1510PF4HGFBAVKA8

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wTJKSESK9HHSS41H0TGVOI30

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wKGQIJB544HC238H03NCE3JK

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wBCP3GICPKS4464H0P5BSC1F

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wEK4QRILNUMLP44H0JQSCJBE

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wF1AGJ756NCL8D9HG6E99V82

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w7TFP7Q1CKHE051HGSBKUVAS

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wRIBV19JSD3NQ18HGMM0FM0K

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w347FM7JNCM5U41HG6B64IMM

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wPQVR4OECK5FLJ8H0IHB2C5E

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wBDMNCG5GUD5921H0E2Q118K

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w8C6JKHD0RQG331H0FD6VPCU

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=wCHJKDHPEG80664HGJ6A0NJ6

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w48J9BBRF3QATQ8HGHBE141M

http://www.flvxplayerdownloads.com/.../mar14.php?subid=marmarlk&sid=w8A13KT50IRLKI8H0FAIID2M

Latest 30 of 431 download URLs

Remove flvplayer-chrome.exe - Powered by Reason Core Security