flashplayerpro-setup.exe

Recode

The application flashplayerpro-setup.exe by Recode has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from files5.mirror4.net.
Publisher:
Recode  (signed and verified)

MD5:
a1380aff554a9dd13ab605bd118fec2a

SHA-1:
79a6c93c86a864b64e2a03feb0240005f151735a

SHA-256:
a7512fe39385deee24afbbe77b47b12b120cad2c16f7d84c12ff1b348a9e0b58

Scanner detections:
14 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
4/19/2024 11:55:51 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.BundleInstaller
2015.04.01

Avira AntiVirus
APPL/Dldr.Admin.iona
3.6.1.96

avast!
Adware-OH [Adw]
2014.9-150401

AVG
Generic
2016.0.3153

Comodo Security
Application.Win32.DownloadAdmin.ANGL
21611

Dr.Web
Threat.Undefined
9.0.1.091

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
9.7.0.302.0

herdProtect (fuzzy)
2015.7.6.5

K7 AntiVirus
Trojan
13.202.15452

Malwarebytes
PUP.Optional.BundleInstaller.A
v2015.04.01.09

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.60253

Reason Heuristics
PUP.Installer.Recode
15.4.1.9

Sophos
Download Admin
4.98

VIPRE Antivirus
Threat.4783369
29708

File size:
802.5 KB (821,728 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashplayerpro-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/13/2014 12:00:00 AM

Valid to:
2/12/2017 11:59:59 PM

Subject:
CN=Recode, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Recode, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7A8465407089FE62D3D2ABC37BC0C4B1

File PE Metadata
Compilation timestamp:
6/22/2012 7:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:qxpJ+TTSc1DM6nKEHJvG9608LytrLlmR+KV/RBTl:WpYT31Y6KSOn8LyJLlmNV

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.4713

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file flashplayerpro-setup.exe has been seen being distributed by the following URL.

Remove flashplayerpro-setup.exe - Powered by Reason Core Security