adobe_flash_setup-133301069.exe

CertFreeCertificateContext

Bicoastal Interactive

The application adobe_flash_setup-133301069.exe by Bicoastal Interactive has been detected as a potentially unwanted program by 21 anti-malware scanners.
Publisher:
Bicoastal Interactive  (signed and verified)

Product:
CertFreeCertificateContext

Version:
9.14.157.518

MD5:
305e1ef2504efce82125d197d8f95be7

SHA-1:
027028b64e64d33e11a37ada46546d0902ff8b6f

SHA-256:
3323f0fcadf3f045f15aba2f20abf37d051255546ccad3c424abb13e65b4d057

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
5/19/2024 9:44:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.20478496
-25

AhnLab V3 Security
PUP/Win32.DownloadAdmin.R195114
3.8.3.16

Avira AntiVirus
TR/Siggen.gkdsw
8.3.3.4

Arcabit
Trojan.Generic.D1387A20
1.0.0.795

avast!
Win32:Rootkit-gen [Rtk]
2014.9-170301

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.1731

Bitdefender
Trojan.Generic.20478496
1.0.20.300

Bkav FE
W32.HfsAdware
1.3.0.8876

Comodo Security
Application.Win32.DownloadAdmin.Y
26677

Dr.Web
Trojan.Siggen7.10262
9.0.1.060

Emsisoft Anti-Malware
Application.AdLoad
8.17.03.01.02

F-Secure
Trojan.Generic.20478496
11.2017-01-03_4

G Data
Trojan.Generic.20478496
17.3.25

IKARUS anti.virus
PUA.DownloadAdmin.Aa
0.2.1.2

McAfee
GenericRXAZ-EG!305E1EF2504E
5600.6109

MicroWorld eScan
Trojan.Generic.20478496
18.0.0.180

Qihoo 360 Security
HEUR/QVM10.1.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
PUP.DownloadAdmin (M)
17.3.1.2

SUPERAntiSpyware
PUP.DownloadAdmin/Variant
8563

Vba32 AntiVirus
Signed-Downware.DownloadAdmin
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
56318

File size:
139.8 KB (143,144 bytes)

Product version:
7.12.96.910

Copyright:
Copyright (C) 2014 Default Browserpos

Original file name:
Taskbar.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\adobe_flash_setup-133301069.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/19/2016 10:50:40 PM

Valid to:
5/19/2017 10:50:40 PM

Subject:
CN=Bicoastal Interactive, O=Bicoastal Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0096C56AE03C38A570

File PE Metadata
Compilation timestamp:
11/29/2016 6:25:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x79BD

Entry point:
E8, BC, 36, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, EC, C4, 41, 00, FF, 15, D0, 50, 41, 00, 85, C0, 75, 18, 56, E8, 0E, 10, 00, 00, 8B, F0, FF, 15, BC, 50, 41, 00, 50, E8, 13, 10, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, CC, B8, 41, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, C3, 3D, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 8D, 85, E4, FC, FF, FF, 6A, 4C, 6A, 00, 50, E8, B7, 3D, 00, 00, 8D, 85, E0, FC...
 
[+]

Entropy:
6.4832

Code size:
77.5 KB (79,360 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-6-18-250.compute-1.amazonaws.com  (52.6.18.250:80)

TCP (HTTP):
Connects to cache.google.com  (204.186.16.168:80)

TCP (HTTP):
Connects to a95-100-170-32.deploy.akamaitechnologies.com  (95.100.170.32:80)

Remove adobe_flash_setup-133301069.exe - Powered by Reason Core Security