flvplayer_downloader-9cipydzx.exe

SITE ON SPOT Ltd.

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application flvplayer_downloader-9cipydzx.exe by SITE ON SPOT has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Somoto BetterInstaller installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from dtusx13epqh0r.cloudfront.net.
Publisher:
SITE ON SPOT Ltd.  (signed and verified)

MD5:
f9e1413d1754146bfe5b8f17ce02e88e

SHA-1:
ab40972d34f721b2c38ffa39a1bf5e7bc0da60cd

SHA-256:
3bf5c60dcad562dd0338f066cff1a4ee2b5125bd4f2bfebe2ae083624465109d

Scanner detections:
21 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 10:39:43 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Somoto-O [PUP]
2014.9-140607

AVG
Downloader
2015.0.3451

Clam AntiVirus
Trojan.Agent-267630
0.98/18355

Dr.Web
Trojan.MulDrop4.11744
9.0.1.0158

ESET NOD32
Win32/Somoto
8.9699

Malwarebytes
PUP.Optional.SiteOn
v2014.06.07.09

NANO AntiVirus
Trojan.Nsis.Mazel.cwhyud
0.28.0.59288

Reason Heuristics
PUP.SITEONSPOT.DD
14.6.12.9

VIPRE Antivirus
Trojan.Win32.Generic
28404

File size:
229.8 KB (235,352 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\flvplayer_downloader-9cipydzx.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/28/2013 1:00:00 AM

Valid to:
6/29/2015 12:59:59 AM

Subject:
CN=SITE ON SPOT Ltd., O=SITE ON SPOT Ltd., L=Tel Aviv, S=NA, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3EE11B140A803DE260823157A875B8C5

File PE Metadata
Compilation timestamp:
12/17/2010 10:14:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
3072:6hizgwyT3BJQ0o9tGlZMY0B/UkoLJpTZM8L9OkKuqrJVYJEgmzm81PGa64PIsIWu:2J380o9tGMY0ZqpHokJ0Tgmzmo+fgAPF

Entry address:
0x380C

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 87, 4D, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 2A, 4A, 00, 00, 6A, 00, E8, 9B, 4D, 00, 00, 6A, 08, A3, 28, F9, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, D8, F9, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, 4C, A2, 40, 00, E8, E0, 4C, 00, 00, 83, EC, 0C, 68, 4D, A2, 40, 00, 68, 08, FA, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, E6, 49, 00, 00, 52, 52, 50, 68, 00, 80, 43, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 29, 49, 00, 00, 83...
 
[+]

Code size:
30 KB (30,720 bytes)

The file flvplayer_downloader-9cipydzx.exe has been seen being distributed by the following URL.

Remove flvplayer_downloader-9cipydzx.exe - Powered by Reason Core Security