installer_adobe_flash_player_english.exe

Gec

The application installer_adobe_flash_player_english.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup program which is used to install the application. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.appsstockgift.com.
Product:
Gec

Version:
2.8

MD5:
a0acc945d39813f01172d7cd5f9114a7

SHA-1:
46fe4da1d2bb747217a6be31048ae4a573195b74

SHA-256:
6c1bce70691cf12c8e71807ee3ed9bca37a407e4ac333ad489930d04b557eb9f

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/7/2025 8:20:01 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware InstallCore.BCP
2015.0.4604

ESET NOD32
Win32/InstallCore.ADC potentially unwanted application
8.0.319.0

Reason Heuristics
Adware.Bundler.ET (M)
16.7.25.18

VIPRE Antivirus
Threat.4786018
50706

File size:
1.2 MB (1,212,416 bytes)

Product version:
2.8

Original file name:
ClickOnceSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\installer_adobe_flash_player_english.exe

File PE Metadata
Compilation timestamp:
2/18/2016 7:49:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:8mSglSwRkwGlt8DB9l00NeC8dlPCrykfjiDnj00++IU764zosR:8XMXR98tC9Bod5a54zos

Entry address:
0x120FDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 03, 00, 00, 00, 28, 00, 00, 80, 0E, 00, 00, 00, 60, 00, 00, 80, 10, 00, 00, 00, 78, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 05, 00, 02, 00, 00, 00, 90, 00, 00, 80, 03, 00, 00, 00, A8, 00, 00, 80, 04, 00, 00, 00, C0, 00, 00, 80, 05, 00, 00, 00, D8, 00, 00, 80, 06, 00, 00, 00, F0, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.1 MB (1,175,552 bytes)

The file installer_adobe_flash_player_english.exe has been seen being distributed by the following URL.

Remove installer_adobe_flash_player_english.exe - Powered by Reason Core Security