flashplayer_setup.exe

Web internet

REGISTERED SECURE

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application flashplayer_setup.exe, “Web internet Setup ” by REGISTERED SECURE has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download the free Adobe Flash Player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Web   (signed by REGISTERED SECURE)

Product:
Web internet

Description:
Web internet Setup

MD5:
7a6b684acc6b0c3e38bc78e77f642fdc

SHA-1:
0db8b14b4a6124ef2c46e68b6c7bb3714c275dc5

SHA-256:
99ba292a9809055a9773000a11f8036f44376a6db1ced2c71bf2364c988b7165

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/17/2024 3:25:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
16.8.27.8

File size:
739.8 KB (757,560 bytes)

Product version:
1.0.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\flashplayer_setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
12/16/2014 4:00:00 PM

Valid to:
12/21/2015 4:00:00 AM

Subject:
CN=REGISTERED SECURE, O=REGISTERED SECURE, L=Seattle, S=Washington, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B6F627B642274865665C8007757783B

File PE Metadata
Compilation timestamp:
6/19/1992 2:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:DlNpDEemEcFD5RqdbwOzUDCFlhkYkRvGmMe6cudwZSN5Vrb3ykyYqpa5xo5A1M86:DlNpEecD5S/DlhkYkh8NdwZUffikFqKy

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove flashplayer_setup.exe - Powered by Reason Core Security