lotpro32.exe

Lotto Pro

Data Solutions

The application lotpro32.exe, “Lotto Pro Installation” by Data Solutions has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from lottopro.ddns.net.
Publisher:
Data Solutions  (signed and verified)

Product:
Lotto Pro

Description:
Lotto Pro Installation

Version:
8.38.0.0

MD5:
ca9fcb94b4d83bbf9924dd22f4b28659

SHA-1:
a92076d4e04bf7055eaef6862e3170706784dd77

SHA-256:
4bd9891a452a8cb0eb287afc6ead58deef1d4632fcac70efc863cdc12d9373b5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/27/2024 10:11:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.2.21.9

File size:
16.7 MB (17,555,896 bytes)

Product version:
8.38.0.0

Copyright:
© Data Solutions

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\lotpro32.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/14/2015 2:00:00 AM

Valid to:
2/5/2016 2:00:00 PM

Subject:
CN=Data Solutions, O=Data Solutions, L=Polk City, S=Florida, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
050DCF11EA3840E80017604CD51D5DFA

File PE Metadata
Compilation timestamp:
8/26/2015 2:01:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x2646DC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 54, BF, 65, 00, E8, B8, 9B, DA, FF, A1, 74, E3, 66, 00, 8B, 00, E8, BC, 14, FB, FF, A1, 74, E3, 66, 00, 8B, 00, BA, 40, 47, 66, 00, E8, DB, 0E, FB, FF, 8B, 0D, 4C, E5, 66, 00, A1, 74, E3, 66, 00, 8B, 00, 8B, 15, F8, D7, 63, 00, E8, AB, 14, FB, FF, A1, 74, E3, 66, 00, 8B, 00, E8, FB, 15, FB, FF, E8, 62, 4B, DA, FF, 00, 00, B0, 04, 02, 00, FF, FF, FF, FF, 05, 00, 00, 00, 53, 00, 65, 00, 74, 00, 75, 00, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9067

Developed / compiled with:
Microsoft Visual C++

Code size:
2.4 MB (2,503,168 bytes)

The file lotpro32.exe has been seen being distributed by the following URL.

http://lottopro.ddns.net/lotpro32.exe

Remove lotpro32.exe - Powered by Reason Core Security