flvplayersetup-ndg3ceqcz.exe

SITE ON SPOT Ltd.

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application flvplayersetup-ndg3ceqcz.exe by SITE ON SPOT has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Somoto BetterInstaller installer.
Publisher:
SITE ON SPOT Ltd.  (signed and verified)

MD5:
714a0fb6249ecd80a8466786f4f1db15

SHA-1:
eaa25d78806362975edf15eceba352572328ae83

SHA-256:
f75ecb66949df10e4aa4e0dff5dc785e4b804e376b665fa3560e394c63f5ad24

Scanner detections:
3 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:36:46 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Adware.Somoto
0.98/213

ESET NOD32
Win32/Somoto
8.9849

Reason Heuristics
PUP.Installer.SITEONSPOT.Y
14.9.19.21

File size:
215.1 KB (220,232 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\flvplayersetup-ndg3ceqcz.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/27/2013 6:00:00 PM

Valid to:
6/28/2015 5:59:59 PM

Subject:
CN=SITE ON SPOT Ltd., O=SITE ON SPOT Ltd., L=Tel Aviv, S=NA, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3EE11B140A803DE260823157A875B8C5

File PE Metadata
Compilation timestamp:
12/17/2010 2:14:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:KA0m3D0oB4ym1GPWui+2qk3dnejPX3Y2ZpUkE1S:KA0iD0oBk1puiCgejPXDZpf

Entry address:
0x39AC

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 97, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 42, 43, 00, 00, 6A, 00, E8, AB, 46, 00, 00, 6A, 08, A3, 88, 4C, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, 38, 4D, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, A4, A2, 40, 00, E8, F0, 45, 00, 00, 83, EC, 0C, 68, A5, A2, 40, 00, 68, 68, 4D, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, FE, 42, 00, 00, 52, 52, 50, 68, 00, D0, 42, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 39, 42, 00, 00, 83...
 
[+]

Entropy:
7.7435  (probably packed)

Code size:
28.5 KB (29,184 bytes)

Remove flvplayersetup-ndg3ceqcz.exe - Powered by Reason Core Security