flvplayersetup.exe

Tas

The application flvplayersetup.exe, “Tas Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Product:
Tas

Description:
Tas Setup

Version:
4.2.4.3

MD5:
c2d525c01d725b41ac4b8b364400c9c2

SHA-1:
501389e9ec46896b48d4929304887b7bcc378bf5

SHA-256:
15926e580fd4d3ac630ecaf46808cc5d5a861e2ca7e81f57a9c98809c3f9d345

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/14/2024 9:05:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE11 (M)
16.5.23.13

File size:
943.3 KB (965,980 bytes)

Product version:
2.3

Copyright:
Web Application Stub

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flvplayersetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:f8kd45IA7fKFt9PBjzxRJ2dltgvV1usB9CnOh+OZ:fXS1iTv3xR2lgTzb7

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file flvplayersetup.exe has been seen being distributed by the following 50 URLs.

http://www.newstockgift.com/WVl6OTRQVlZCWkVGMk9HTnRTbUY1UWxSWlpFaGpaVzlMYlhZd1dESkxOMmRwTWpneVVteG1ka05qTWxOaWFVRWxNMFFtWXoxR1VDVXlSbUpZYzB4NlptaGtjVmxxYkZka2EwbFFORXdsTWtJeVZHUlNlbGhPU1dKaFYwVmhjVE5xVEhkd1JIQkpTalI1VnpGSFVFTXdaRFIxVFRkaFRVOWFaRk5EYjJjMlNYVkllVTlCYkVsNFRrZFliVGRxYmpOT1NIQlJhRGR2VlVwdlJWbFlZMDl2UjIweWFrRXlKVEpDV2pFelRqRjZTR3hsYzBoaFVFbDZVMEpzSlRKRw==

http://www.jdmdacnowapp.com/WVl6OTRQVUZ0V21sSE5EQkZNRzVCU1c1MmNqWkpSbWdsTWtKek5YaEZhV0Y1UzFSa1V6aHVVMHhhTlVoM04yeDJjeVV6UkNaalBYZFVSa2RUVDBSUVpDVXlRbVpFUjNsWlVGTldNbFpJT1VGNWJGaFJlRWhvT0dKUWNUQlVaQ1V5UWpkQk1uWm1UQ1V5Umxoc01rTTBOMWRTTVUxRk4wMGxNa1phSlRKR05HWjJNVmgwTUZjMVptNDBhM2hOY25odmEyNUdZVEZrYWsxMWNHeHRhSFJ1Y21wdGRtY2xNa0pzVFhwVlR6TkZSWEJZVUVKc2NTVXlSbEpIWjNKQmRVcFpUVmc1TmxjPQ==

http://www.newstockgift.com/WVl6OTRQV1pLYWxsaGVtZE9OV2wzVWt0WFREaGhSV0ptWld0ME9FVTRaVzRsTWtaR04wcEdTRGRZVDJwcGQxVk5OQ1V6UkNaalBUSXhOMFZ3SlRKQ09YZ3dlbEZuTWxWNVRETkVWVEp3VFhsSGVWZzVWa051UWpFM1ZGQTNPRGRFYUhkWmIzSmFjVkp3VmtGWGJtZHhRVGN3YTBOUVdYWlhZMlZzZGtWdFNVWTRRbU5pWTNaNE1tdEVja3MxTjBWcWNESjNTSGRPVTNKUmNFVkhiVlE0TnlVeVJqQnNhMHhyVm0xUE1HTklkV0kyY0dRd01YaFhTazA1YVE9PQ==

http://www.jdmdacbinariesdl.com/WVl6OTRQVVZhYkZsNFdHTkphRlZSZERZbE1rWTNkbGxTV1hnbE1rWlpka3BRUzNrbE1rSlZUeVV5UmxsV0pUSkNTbmRuTlVSYVpVazRKVE5FSm1NOWNETktRVE4xUmt0SE9VZ2xNa0l3Um05T1UzZFVNRlJYZEdRME1tWnhiVzFCYW1zeFVrbGpkMEZyTXlVeVFtOHhRMEV5SlRKR2NFRnRRbEJqUVdGM01VaFJNbUZNY0RkT2RVRnpWVThsTWtaUWJXUTJkMVpRUzNKeE0ySjRjVXhDVm5oT04zTlZiVGh1U25ZbE1rWmthMHBwVFRSUE5uUnZSVnAzVVVGNmFrZGhha3hVTjBJeGJuQnQ=

http://www.jdmdaccyclenow.com/WVl6OTRQV05CYzFJNGNDVXlRbFZPZDJGRlNrYzFZM0JHTVVnbE1rSjBiVEp1Vm1aSGVVTXhKVEpDUTNGbE5HaDRXRVExVTBrbE0wUW1ZejFGV25CaVExSkxWRWhNY210ak5sTjVWamxRV2tkeVpXRTVRekkxTVdKNGFrOXRkRTB6Y1hOUFkydzBWV0ZtVmtGRlZFMXRWRmtsTWtJeUpUSkdOU1V5Um5SU1JUTnBjeVV5Um1WSVdtRjBabmRQT1cweFdVaFBSRkZZZFZob09FMDRha0UzYjA4MFJUWkZVSE5YUTNSaVRFWk9NU1V5Um5CMGVsWXhUREprU2tkRVJWZFhiMjk2TlhZPQ==

http://www.jdmdacconecptsafe.com/WVl6OTRQVTF3Y2s1dU1uVlhabU5HU1habWFpVXlSa1EzYzFoM1JHRkxkMGR2U2lVeVJqQTJWMVIxTTBOTlNtcFJaM2MwSlRORUptTTlVbTgyZDBsWGVrdExjM2hxYjI1dFVreEhkWEY0TTNaVU5YRlNPV05WZFVSaWVVeDJWM0p4TUdodWJsVWxNa0pDTVcwMGRWaEtKVEpDYzFGQmIxSmpialUzYjJWSlNVcFBSVUZLVGs5TGFuaEVja3RzY2t0NWMwRlFNRmQ2TUdscWNIbEZXazF3ZUZSSmEwbGhlbEp5UzBkR1FrTmxVRFZ2SlRKR2MwUndhazl6Vm1aMlNtOD0=

http://www.updaterepositorytown.com/WVl6OTRQWE1sTWtJNFluTjJOMm80YW05NlRUUWxNa0pqTVU4M2RDVXlRblJQWTFaS0pUSkNkM1pqV21GeFYySlpjVk40WjBVeVVTVXpSQ1pqUFdkTFFqTk5lakY0TlVOdFJWbHRiVGhSZGxsc1FWaDFNM1JZU1cwMVF6ZHBkbVU1U2pOYVRqSndlR2Q0ZERoaVUwSlVRVWc0TjFaV05WbzRRbEpCUjBKcFNFZE5ObkJPT1d0NFJETklhREZ5SlRKR2RHWlpiMEU1TmxOelVXeGlKVEpHYkRSbmJIVnBUM1ZGTnpOWVlYVldWbXBrTmt0SWEyTjJTblpPZEVSd1luZzNPUT09

http://www.updaterepositorytown.com/WVl6OTRQVWh3VEU5SFNXWnNRMXBPUjJkUGFVNU9NMEp2UTJaM1VEbEJNbk5DWTBKelJ6STFlRTlWUkRZNWJrRWxNMFFtWXowNFoySnhhMWwzYlVwa1ZHNVJKVEpHY1hacGFVaExVR2hXWm05Q1lYaHVNa2MzTUhCNVkwWlZjbVJ4YjNGeVptczRUa3hrWjNKNWQxUnJibFppVWpWb01tVlZkRE5uVGlVeVFsQWxNa1p2VXpoS2JVZHdTa05LTkVReVNHdDJibmhvTmxoRmFuZHFVV2c0YVhBek1GUjFZVE0yYUNVeVFsUnBNVFZKYUVWVVlqZHRZa054YVRjMg==

http://www.jdmdacbinariesdl.com/WVl6OTRQU1V5UWpJMlRHVnpRalpPYmtSaWRVRlROelowYUZwa1RpVXlRbmR6WmxVMlFVUnZkMFZJZFhSVlIwNXFlbEJuSlRORUptTTljMDFyWXlVeVJsUk5OMk13YTI1a2FWZEpWelJRWVVkdFIwWTVabGhQY0dWVlZGYzNjMVJQWkRKaVVGSllhaVV5UWpGWFJXWkNZa1pqYTBVNVVqTnNXVGRHZDJkSmJpVXlRakpsVDNNMlYxRlVTRkpzZVdzMVUxSkJNMk54YW5OeVpURnNORXRNYUdoTlpqWkhlRFJHY21oa2EydDFaamw2Y0Roa2ExVmplVmhCTm5WcFdYUT0=

http://www.jdmdaccyclenow.com/WVl6OTRQWFZyYlRrbE1rSkVkMGxCV2tsRU9XVnNSVWg1YTNwRFYwVkhWSGhQU2pscFdGTlpPRlp0T0U5NlNrdEdkeVV6UkNaalBWcDZlVFJZUkVRM1JucDZZVmh4WjNNd01UWWxNa0pFYjNVd2Eyb3phMUZ6U0cxS2IydEZTMFI2U0dWQlUwcFJOVXhXZWtwWGFuWk9WRU5WWkhSb1ZXUnVKVEpHZURGbmRHdzFkRWN5UkRBelpsbEROMmw1V0RSRFRtUTVOa05PTmxOWFZHRnVRMk1sTWtack1XSlNaV280UTNjeVZHdHFlall4ZVhCUlkyUjBSM1puUjNkNg==

Latest 30 of 52 download URLs

Remove flvplayersetup.exe - Powered by Reason Core Security