flvplayersetup-n5oqcflmr.exe

The program is a setup application that uses the Nullsoft Install System installer. The file has been seen being downloaded from www.down1oads.com a known adware distribution point operated by Somoto Ltd..
MD5:
4aee69dedf187ce7920b3194b8d4bdb5

SHA-1:
5b3182dc8798f8c76291d9ec30913978545075fc

SHA-256:
9dc5ffc712ffb022fe5991acd1e8db61d70d941ba80c21ce244cee9898dd860e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 2:09:32 PM UTC  (today)

File size:
303.4 KB (310,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\flvplayersetup-n5oqcflmr.exe

File PE Metadata
Compilation timestamp:
12/17/2010 4:14:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:tJ380olffDbrJ+JGMY0Zq7aPIi7cNnSsBtwoFnIgAPx:tF80oF/rJCG74PKSohIJ

Entry address:
0x380C

Entry point:
F6, C0, A3, 85, FD, 86, C3, 72, 0D, 2A, E6, 8D, 05, 4C, FF, 2F, E0, 2D, 66, 01, B8, B5, 80, C6, 83, 8D, 05, 8C, AF, 0B, EB, 42, C7, C7, 19, BE, 09, 58, 81, FE, 74, 2F, 00, 00, 70, 04, 89, E8, 84, E5, 8B, D3, 8B, EF, 35, F5, EF, F2, AF, 1D, 7C, 07, 0A, 98, 03, CD, 69, C1, 0C, AE, 24, A6, FF, CB, 50, 52, C6, C1, 2E, C7, C7, A8, 33, 9F, 7A, 8A, EF, 0F, B6, F2, 80, E6, E7, F6, C4, 4E, E8, 27, 00, 00, 00, 29, CA, 69, DB, BA, E8, 82, 0E, 69, FE, 41, DD, FA, 9E, C7, C0, FD, 82, 37, 44, 30, C5, C6, C6, D4, C7, C2...
 
[+]

Entropy:
7.8408  (probably packed)

Code size:
30 KB (30,720 bytes)

The file flvplayersetup-n5oqcflmr.exe has been seen being distributed by the following URL.

Scan flvplayersetup-n5oqcflmr.exe - Powered by Reason Core Security