installer_adobe_flash_player_english.exe

Onekit Internet

The application installer_adobe_flash_player_english.exe by Onekit Internet has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the OneKit Downloader installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from wosoxoko74663hiwilix.kicireupafoy.info.
Publisher:
Onekit Internet  (signed and verified)

MD5:
c4f768f55a1bc6c0c18f5dbd9eee13a9

SHA-1:
4208cd8f108ad72ed41896519b85a8c143b67aa0

SHA-256:
bdc01c5b16da18fc58970b487e1f867cea647d4552cc0cfdccb2c6e5c3c8e5d9

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
1/15/2025 11:41:59 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
Onenet
2016.0.3100

Dr.Web
Trojan.Vittalia.34
9.0.1.05190

ESET NOD32
Win32/TrojanDropper.Addrop.C trojan
7.0.302.0

Malwarebytes
v2015.05.23.03

Reason Heuristics
PUP.Installer.OnekitInternet
15.6.7.12

VIPRE Antivirus
Threat.4783369
40432

File size:
1 MB (1,096,312 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OneKit Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_adobe_flash_player_english.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/5/2015 1:00:00 AM

Valid to:
3/5/2016 12:59:59 AM

Subject:
CN=Onekit Internet, O=Onekit Internet, L=Cerdanyola del valles, S=Barcelona, C=ES

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
40744793F55F4350CB4D2F030795E67F

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:CS6qaHMoJqpc4+Mtm/TK2GJ/5jLK8wpYxJh7o1Uf1a4HgwtosY4ZiNvuQ5yQ0:faMoJq9+MtiTQVe8wyzaefc4NtHAN2Qy

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9920

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_adobe_flash_player_english.exe has been seen being distributed by the following URL.

Remove installer_adobe_flash_player_english.exe - Powered by Reason Core Security