lotpro32.exe

Lotto Pro

Data Solutions

The application lotpro32.exe, “Lotto Pro Installation” by Data Solutions has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from lottopro.ddns.net.
Publisher:
Data Solutions  (signed and verified)

Product:
Lotto Pro

Description:
Lotto Pro Installation

Version:
8.36.0.0

MD5:
562ed525188e5e4c5f72c4af6e35a714

SHA-1:
d7c37c8eb9cbbd7b77c070c9a872c0186e88e1b8

SHA-256:
4cab8e078d91f1cd941177d6bdd1333fc803ee59d2a44db85838f8f48f8841ba

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/9/2024 1:08:30 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.12.9.11

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16106

Zillya! Antivirus
Adware.BrowseFox.Win32.137416
2.0.0.2573

File size:
16.7 MB (17,460,816 bytes)

Product version:
8.36.0.0

Copyright:
© Data Solutions

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\lotpro32.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/13/2015 6:00:00 PM

Valid to:
2/5/2016 6:00:00 AM

Subject:
CN=Data Solutions, O=Data Solutions, L=Polk City, S=Florida, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
050DCF11EA3840E80017604CD51D5DFA

File PE Metadata
Compilation timestamp:
8/26/2015 7:01:27 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:f50cpqlzt6SOGsO36JmY4lSE0FltZk7uhO30Y/4UXha6rEf055tGRGJrF7dwVvs7:fKIKAGsC6JmotZk7ucQUZGgVltGvxMd

Entry address:
0x2646DC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 54, BF, 65, 00, E8, B8, 9B, DA, FF, A1, 74, E3, 66, 00, 8B, 00, E8, BC, 14, FB, FF, A1, 74, E3, 66, 00, 8B, 00, BA, 40, 47, 66, 00, E8, DB, 0E, FB, FF, 8B, 0D, 4C, E5, 66, 00, A1, 74, E3, 66, 00, 8B, 00, 8B, 15, F8, D7, 63, 00, E8, AB, 14, FB, FF, A1, 74, E3, 66, 00, 8B, 00, E8, FB, 15, FB, FF, E8, 62, 4B, DA, FF, 00, 00, B0, 04, 02, 00, FF, FF, FF, FF, 05, 00, 00, 00, 53, 00, 65, 00, 74, 00, 75, 00, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9056

Developed / compiled with:
Microsoft Visual C++

Code size:
2.4 MB (2,503,168 bytes)

The file lotpro32.exe has been seen being distributed by the following URL.

Remove lotpro32.exe - Powered by Reason Core Security