installer_adobe_flash_player_english.exe

The application installer_adobe_flash_player_english.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from dv.a-chn4.com and multiple other hosts.
MD5:
4aeb56d1c5e8548c5df27637739225b8

SHA-1:
39c0de6fd873de2f704303aef648126f3bca6469

SHA-256:
f1dd309f4190947a54474d6b0479b05e26277fb93a076d09279828535c9d9a05

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 4:38:38 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/TrojanDropper.Addrop.B trojan
7.0.302.0

Kaspersky
not-a-virus:Downloader.NSIS.Agent
15.0.0.543

McAfee
Trojan.Artemis!4AEB56D1C5E8
18.0.204.0

VIPRE Antivirus
Threat.4150696
42502

File size:
676.9 KB (693,153 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\installer_adobe_flash_player_english.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:MOvEGfgs+Y/TPy3hDe3I9Q/UdMxKdnUeOWkFevXaRF/1dmSacrxzGO62F:MOMxMAxeaQsdMx8njOWk0+/1dXacrxCK

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9769

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_adobe_flash_player_english.exe has been seen being distributed by the following 3 URLs.

http://dv.a-chn4.com/installers/axtan_installers/get.php?ua=chrome&ut=4101a032a1310a8a699d19e8bf9a0af1&r=2382312&p=RlJFRVNPRlRTVE9SRUNPTQ==&x=L2hvbWUvZG93bl9jcm9ucy9wdWJsaWNfaHRtbC9pbnN0YWxsZXJzL291dC9vbi8yL2ZyZWVzb2Z0c3RvcmVjb20vZW5nbGlzaC9yZXZlbnVlL2Nocm9tZS9hZG9iZV9mbGFzaF9wbGF5ZXIvZC8yNzU4NzZlMzRjZjYwOWRiMTE4ZjNkODRiNzk5YTc5MC9vdXQvbmEvbmEvaW5zdGFsbGVyX2Fkb2JlX2ZsYXNoX3BsYXllcl9FbmdsaXNoLmV4ZQ==&u=L2Rvd25sb2FkMi5mcmVlc29mdHN0b3JlMi5jb20vaW5zdGFsbGVycy9vdXQvMDAyMDQwMDIwNTAwMjA2L3BpaWQtNTRkMzg0OGYxY2QyMDMuNzYyODg0Nzgvb24vMi9mcmVlc29mdHN0b3JlY29tL2VuZ2xpc2gvcmV2ZW51ZS9jaHJvbWUvYWRvYmVfZmxhc2hfcGxheWVyL2QvMjc1ODc2ZTM0Y2Y2MDlkYjExOGYzZDg0Yjc5OWE3OTAvb3V0L25hL25hL2luc3RhbGxlcl9hZG9iZV9mbGFzaF9wbGF5ZXJfRW5nbGlzaC5leGU=&loop=1&aa=on/2/freesoftstorecom//&CL=59&FE=20&NE=78&IM=88&MG=72&EM=39&JG=90&EN=76&DM=52&s=3761291550309838581410038902877254474530670654412663766667855670118561528694035201678335020697608555618577081511779613226285056902573331139390578430862491096697845288391330488221308657

http://dv.a-chn4.com/installers/axtan_installers/get.php?ua=chrome&ut=2890d460e4c113cccc369f4281a0399b&r=8051810&x=L2hvbWUvZG93bl9jcm9ucy9wdWJsaWNfaHRtbC9pbnN0YWxsZXJzL291dC9vbi8yL2ZyZWVzb2Z0c3RvcmVjb20vZW5nbGlzaC9yZXZlbnVlL2Nocm9tZS9hZG9iZV9mbGFzaF9wbGF5ZXIvZC8yNzU4NzZlMzRjZjYwOWRiMTE4ZjNkODRiNzk5YTc5MC9vdXQvbmEvbmEvaW5zdGFsbGVyX2Fkb2JlX2ZsYXNoX3BsYXllcl9FbmdsaXNoLmV4ZQ==&loop=1&p=RlJFRVNPRlRTVE9SRUNPTQ==&u=L2Rvd25sb2FkMi5mcmVlc29mdHN0b3JlMi5jb20vaW5zdGFsbGVycy9vdXQvMDAyMDQwMDIwNTAwMjA2L3BpaWQtNTRkMzdlMzEyNWM4MTQuMjI4MDYwNDgvb24vMi9mcmVlc29mdHN0b3JlY29tL2VuZ2xpc2gvcmV2ZW51ZS9jaHJvbWUvYWRvYmVfZmxhc2hfcGxheWVyL2QvMjc1ODc2ZTM0Y2Y2MDlkYjExOGYzZDg0Yjc5OWE3OTAvb3V0L25hL25hL2luc3RhbGxlcl9hZG9iZV9mbGFzaF9wbGF5ZXJfRW5nbGlzaC5leGU=&aa=on/2/freesoftstorecom//&IG=97&EF=80&GF=75&IE=97&AM=7&BB=83&IH=80&ML=98&NK=82&BD=5&s=545880243334490379082069978776820308433766206334242549447324917948891168798322756001056888379074953160949782067778883562499307892219304383589367155501741781471792733261520457172722

Remove installer_adobe_flash_player_english.exe - Powered by Reason Core Security