flvplayer_v4.exe

Click run software

The application flvplayer_v4.exe by Click run software has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.yoursportmanager.com.
Publisher:
Click run software  (signed and verified)

MD5:
21030cce22d62eba835cb2d20b3314d0

SHA-1:
b3657f6663725c728255a579c3ddc7acca543e2f

SHA-256:
d61c138987fbc1ed2aed671d72ca4354a01929b2f53e47292644320bdc636268

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/17/2024 12:42:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Clickrunsoftware (M)
16.1.9.15

File size:
1.1 MB (1,114,896 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\flvplayer_v4.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/18/2012 9:00:00 PM

Valid to:
4/19/2013 8:59:59 PM

Subject:
CN=Click run software, O=Click run software, STREET=63 Rotshylid Shderot, L=Tel-Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A243E49C0DAF69F7C5ACF083EB184161

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:RUp9ToJ9BTh+rrDP4KkhnjCkCDFRTSEXoTj7g1o:WpKT+HDgKkhjXWfT5XQ7

Entry address:
0xC1772

Entry point:
55, 8B, EC, 83, C4, F0, B8, A7, E0, 40, 00, E8, E4, E4, FF, FF, B7, 15, 07, 8B, 7D, F9, 64, F4, CF, CE, 52, AF, FD, CF, 19, 66, 33, C5, 0B, 9F, 99, E4, EE, A6, 52, E3, 4B, 95, 15, 32, 64, 17, 73, 90, 33, C4, 1E, 88, A4, 3A, A9, 7D, E7, 36, A6, 59, A5, 65, 17, 02, 57, BB, 90, 24, 1D, 6E, 87, 05, D2, EB, AE, 60, 3C, 77, 51, 7C, 7C, 33, 11, 09, 49, C7, 89, 72, 7C, F4, A0, AA, F8, B0, 91, A6, 0B, B5, 0E, 0A, A6, 86, E3, B8, 4B, 62, 11, 56, 51, A6, 3E, E0, F5, 98, F3, ED, 6F, 91, 15, 3E, CE, 0B, 6E, AD, 8D, 0E...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
787 KB (805,888 bytes)

The file flvplayer_v4.exe has been seen being distributed by the following URL.

Remove flvplayer_v4.exe - Powered by Reason Core Security