{"id":2381,"date":"2014-10-25T18:52:41","date_gmt":"2014-10-25T18:52:41","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=2381"},"modified":"2018-05-29T12:01:56","modified_gmt":"2018-05-29T12:01:56","slug":"ooo-finans-servis-virustotal-report","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/ooo-finans-servis-virustotal-report\/","title":{"rendered":"OOO &#8220;Finans Servis&#8221; &#8211; 9% Detection Rate: InstallCore\/CryptInno"},"content":{"rendered":"<p>Just wanted to give you the heads up on files digitally signed by <strong>OOO &#8220;Finans Servis&#8221;<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2390\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-publisher.png\" alt=\"OOO Finans Servis publisher\" width=\"485\" height=\"281\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-publisher.png 485w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-publisher-300x173.png 300w\" sizes=\"(max-width: 485px) 100vw, 485px\" \/><\/a><\/p>\n<p>The OOO &#8220;Finans Servis&#8221; certificate shows that the publisher is located in Moscow in Russia.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2388\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-certificate.png\" alt=\"OOO Finans certificate\" width=\"504\" height=\"550\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-certificate.png 504w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-certificate-274x300.png 274w\" sizes=\"(max-width: 504px) 100vw, 504px\" \/><\/a><\/p>\n<p>The problem here is that the OOO Finans Servis was promoted as an update for Adobe&#8217;s Flash Player. If <strong>adobe_flash_setup.exe<\/strong> really was a setup file for <strong>Adobe Flash Player<\/strong>, it should be digitally signed by <strong>Adobe Systems Incorporated<\/strong> and not by some unknown company located in Moscow.<\/p>\n<p>9% of the anti-malware scanners detected the file. <strong>PUP.Optional.InstallCore<\/strong> and <strong>BehavesLike.Win32.CryptInno.bc<\/strong> were two of the detection names. I think we will see the other anti-virus programs add this one to the detection list soon.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-virustotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-2391\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-virustotal.png\" alt=\"OOO Finans Servis virustotal\" width=\"764\" height=\"388\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-virustotal.png 764w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/OOO-Finans-Servis-virustotal-300x152.png 300w\" sizes=\"(max-width: 764px) 100vw, 764px\" \/><\/a><\/p>\n<p>Since you probably came here after finding a file that was digitally signed by <strong>OOO Finans Servis<\/strong>, please share what kind of download it was and if it was detected by the anti-malwares at VirusTotal.<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just wanted to give you the heads up on files digitally signed by OOO &#8220;Finans Servis&#8221;. The OOO &#8220;Finans Servis&#8221; certificate shows that the publisher is located in Moscow in Russia. The problem here is that the OOO Finans Servis was promoted as an update for Adobe&#8217;s Flash Player. If adobe_flash_setup.exe really was a setup &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/ooo-finans-servis-virustotal-report\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">OOO &#8220;Finans Servis&#8221; &#8211; 9% Detection Rate: InstallCore\/CryptInno<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[181,104],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2381"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=2381"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2381\/revisions"}],"predecessor-version":[{"id":2392,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2381\/revisions\/2392"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=2381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=2381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=2381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}