lotpro32.exe

Lotto Pro

Data Solutions

The application lotpro32.exe, “Lotto Pro Installation” by Data Solutions has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from lottopro.ddns.net.
Publisher:
Data Solutions  (signed and verified)

Product:
Lotto Pro

Description:
Lotto Pro Installation

Version:
8.34.0.0

MD5:
bd25a2489345cf77da0c4217726c7805

SHA-1:
c99e113c84098ae404ceef3a80e845057d83a9c3

SHA-256:
300ab82b980dbe52bd525fdc25b48175ed4302788647e113b7c830fc2a179afe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/8/2024 8:10:27 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.12.12.18

File size:
16.6 MB (17,419,000 bytes)

Product version:
8.34.0.0

Copyright:
© Data Solutions

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\lotpro32.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/14/2015 12:00:00 AM

Valid to:
2/5/2016 12:00:00 PM

Subject:
CN=Data Solutions, O=Data Solutions, L=Polk City, S=Florida, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
050DCF11EA3840E80017604CD51D5DFA

File PE Metadata
Compilation timestamp:
8/26/2015 1:01:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x2646DC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 54, BF, 65, 00, E8, B8, 9B, DA, FF, A1, 74, E3, 66, 00, 8B, 00, E8, BC, 14, FB, FF, A1, 74, E3, 66, 00, 8B, 00, BA, 40, 47, 66, 00, E8, DB, 0E, FB, FF, 8B, 0D, 4C, E5, 66, 00, A1, 74, E3, 66, 00, 8B, 00, 8B, 15, F8, D7, 63, 00, E8, AB, 14, FB, FF, A1, 74, E3, 66, 00, 8B, 00, E8, FB, 15, FB, FF, E8, 62, 4B, DA, FF, 00, 00, B0, 04, 02, 00, FF, FF, FF, FF, 05, 00, 00, 00, 53, 00, 65, 00, 74, 00, 75, 00, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9056

Developed / compiled with:
Microsoft Visual C++

Code size:
2.4 MB (2,503,168 bytes)

The file lotpro32.exe has been seen being distributed by the following URL.

http://lottopro.ddns.net/lotpro32.exe

Remove lotpro32.exe - Powered by Reason Core Security