icreinstall_installer_adobe_flash_player_english.exe

Free Software LLC

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_installer_adobe_flash_player_english.exe by Free Software has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the installCore installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from clkmon.com. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Free Software LLC  (signed and verified)

MD5:
d23bd65a3bf0e3f72cfef33d382cc5df

SHA-1:
13e3a865f701ac188e9eae11190215b551fffc0d

SHA-256:
34c7ac98d7279a6d58242cf42df899434ffa151a5899930379dee8eccabbbb02

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 7:04:16 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.205.34

AVG
Generic
2016.0.3218

Baidu Antivirus
PUA.Win32.Vittalia
4.0.3.15126

Dr.Web
Trojan.DownLoad3.35287
9.0.1.05190

ESET NOD32
Win32/InstallCore.SC potentially unwanted application
7.0.302.0

K7 AntiVirus
Trojan
13.192.14749

Malwarebytes
PUP.Optional.BundleInstaller
v2015.01.26.04

Reason Heuristics
PUP.FreeSoftware
15.1.26.4

VIPRE Antivirus
Threat.4782551
36666

File size:
793.5 KB (812,592 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_installer_adobe_flash_player_english.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
8/1/2014 5:08:01 PM

Valid to:
7/22/2015 6:23:49 PM

Subject:
CN=Free Software LLC, O=Free Software LLC, L=Wilmington, S=Delaware, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27DD6AADCC34E6

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:vKFTIENy3+ZSijrkfj0NF3I1zG8gnqZuDUYp799Sp:vYUrijrkfjOF41hgq4UYD8

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8869

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icreinstall_installer_adobe_flash_player_english.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)