flash___click_to_safe_install___________________________ma2_0_9509_640161_gc.exe

Start Install

The application flash___click_to_safe_install___________________________ma2_0_9509_640161_gc.exe by Start Install has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.cooct13hen.com.
Publisher:
Start Install  (signed and verified)

MD5:
68ca1413bb2264f7d88c40824aa0bb1c

SHA-1:
5b54510522e921c0b5ab22095ead4831c97bbeb3

SHA-256:
1a6ba0a7c04a45957e4198ca05db6f8440cf90f9eaa173475cd2bb9197eb4485

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/7/2024 10:08:49 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Malware-gen
140813-1

AVG
Generic
2015.0.3358

ESET NOD32
Win32/InstallMonetizer.BC potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.SilenceInstaller.A
v2014.09.08.03

McAfee
Artemis!D941EF050346
5600.7014

Reason Heuristics
PUP.StartInstall.
14.9.8.2

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.14906

Trend Micro House Call
Suspici.F184F561
7.2.251

File size:
493.3 KB (505,168 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\flash___click_to_safe_install___________________________ma2_0_9509_640161_gc.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/26/2014 7:00:00 PM

Valid to:
1/27/2015 6:59:59 PM

Subject:
CN=Start Install, O=Start Install, STREET=5655 Silver Creek Valley Road, L=San Jose, S=CA/Santa Clara, PostalCode=95138, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4A35F3F064DE91E511E0079B2961EAAF

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Msn8FPp5UkallMCBp6p8fbJd5AgAeybJd5A8e:Msn8lUkalWCfFfbJd5AgAeybJd5A8e

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.7510

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file flash___click_to_safe_install___________________________ma2_0_9509_640161_gc.exe has been seen being distributed by the following URL.