icreinstall_adobe_flash_setup.exe

Software web

OOO Mad Advert

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_adobe_flash_setup.exe, “Software web Setup ” by OOO Mad Advert has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from pleaseupdate.theperferct24updater.net. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Application Generic   (signed by OOO Mad Advert)

Product:
Software web

Description:
Software web Setup

Version:
2.5.1.4

MD5:
59c688eb3f8527e6d20ebec23be604a4

SHA-1:
dd6f02f450a393a3ad9d9b3e5cfc6a1b02499295

SHA-256:
97e9689986f9817e8976b2018a46d91d1976cc5517daa18da85f50dc7cf3b725

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 1:38:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.OOOMadAd.Installer (M)
16.5.9.13

File size:
758.1 KB (776,264 bytes)

Product version:
2.8

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_adobe_flash_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/18/2015 5:00:00 PM

Valid to:
3/18/2016 4:59:59 PM

Subject:
CN=OOO Mad Advert, O=OOO Mad Advert, STREET="Andronevskaya B., d. 7/14 str. 1 of. 1205", L=Moscow, S=Moscow, PostalCode=109544, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0080C5CB45D047D2C30BE1A2662DE771D1

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:pceGubtRouzqw1/X+TXriAPom9ec4BFeEkCmf2Vqdn7eTGlXtzYslydvg:pcedtRhzqw1/OjrLf9I4Cm+Vi7zXtzii

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8042

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_adobe_flash_setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_adobe_flash_setup.exe - Powered by Reason Core Security