flvplayersetup-n5hevrpfw.exe

The program is a setup application that uses the Nullsoft Install System installer. The file has been seen being downloaded from www.downloadab.com a web site host known to distribute potentially unwanted software operated by Somoto Ltd..
MD5:
addf32c0e13577a4817d89f4c04b91d0

SHA-1:
2fdd238cc57d6329271b0f649cb9ffde79134121

SHA-256:
9825f426fcc837920e4a0a1a36735c9f581909a23c8b7f2e9138a0a96db4d750

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:30:14 PM UTC  (today)

File size:
303.4 KB (310,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\flvplayersetup-n5hevrpfw.exe

File PE Metadata
Compilation timestamp:
12/17/2010 4:14:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:gmJ380ox8eanzpdMh+Iy6brxwQGMY0ZqFpOWFu13LXAybBTfHogAPd:gmF80ox8r9Wh+rqV9G7ngWFU7vbtHo1

Entry address:
0x380C

Entry point:
69, F5, AF, C9, E8, 0B, F7, C2, 6A, A0, 5E, 6A, FE, C0, 73, 02, 23, D0, 8D, 3D, 0C, 47, 2F, C8, 81, DB, 82, 4C, E8, 99, F7, C2, F7, D1, F9, 40, B0, D0, BA, BD, 09, 60, A2, 69, D6, 18, 84, 3B, 13, 8D, 3D, 95, 67, FD, 1F, B0, F7, FF, CE, 0F, BF, C6, 8D, 0D, CD, 70, 48, A1, 8D, 15, 01, 04, 98, 32, E8, 20, 00, 00, 00, FF, C2, F2, 4D, 8A, F2, C7, C7, FA, BD, B4, 47, B8, 0D, 3C, 9D, E6, 33, F6, F6, C7, 53, 69, C0, 32, 48, 18, BF, 8D, 1E, 88, D2, 5A, 85, EE, 78, 05, 1D, 9B, 47, F9, 96, 23, EA, C6, C0, 24, 8D, 3D...
 
[+]

Code size:
30 KB (30,720 bytes)

The file flvplayersetup-n5hevrpfw.exe has been seen being distributed by the following URL.

Scan flvplayersetup-n5hevrpfw.exe - Powered by Reason Core Security