{"id":7119,"date":"2015-08-31T21:48:59","date_gmt":"2015-08-31T21:48:59","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=7119"},"modified":"2015-08-31T21:48:59","modified_gmt":"2015-08-31T21:48:59","slug":"ooo-digital-vei-18-detection-rate-installcore","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/ooo-digital-vei-18-detection-rate-installcore\/","title":{"rendered":"OOO DIGITAL VEI &#8211; 18% Detection Rate &#8211; InstallCore"},"content":{"rendered":"<p>Hello readers! Just a quick post on a publisher called <strong>OOO DIGITAL VEI<\/strong> that I found while running some tests for the upcoming FreeFixer release. The suspicious file is named adobe_flash_player.exe.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7123\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-publisher.png\" alt=\"OOO DIGITAL VEI publisher\" width=\"499\" height=\"292\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-publisher.png 499w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-publisher-300x175.png 300w\" sizes=\"(max-width: 499px) 100vw, 499px\" \/><\/a><\/p>\n<p>Viewing the certificate information is also possible by looking under the digital signature tab for the file. Here the certificate says that OOO DIGITAL VEI is located in Moscow, Russa.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7121\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert.png\" alt=\"OOO DIGITAL VEI cert\" width=\"387\" height=\"414\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert.png 387w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert-280x300.png 280w\" sizes=\"(max-width: 387px) 100vw, 387px\" \/><\/a><\/p>\n<p>And USERTrust and Comodo is upwards in the certificate chain:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert-chain.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7122\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert-chain.png\" alt=\"OOO DIGITAL VEI cert chain\" width=\"307\" height=\"204\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert-chain.png 307w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-cert-chain-300x199.png 300w\" sizes=\"(max-width: 307px) 100vw, 307px\" \/><\/a><\/p>\n<p>What caught my attention was that the download was called adobe_flash_player.exe. This might look like an official <strong>Adobe Flash Player<\/strong> download, but it is not. If it was an official download, it should be digitally signed by <strong>Adobe Systems Incorporated<\/strong>. Here&#8217;s how the <strong>authentic Adobe Flash Player<\/strong> looks like when you double click on it. Notice that the &#8220;Verified publisher&#8221; says &#8220;Adobe Systems Incorporated&#8221;.<br \/>\n<a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-3187\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer.png\" alt=\"Adobe Systems Incorporated - Adobe Flashplayer Installer\" width=\"534\" height=\"324\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer.png 534w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/11\/Adobe-Systems-Incorporated-Adobe-Flashplayer-Installer-300x182.png 300w\" sizes=\"(max-width: 534px) 100vw, 534px\" \/><\/a><\/p>\n<p>The problem with the OOO DIGITAL VEI file is that it is detected by many of the antivirus software. Here are some of the detection names: W32.HfsAdware.90CE, PUP.Optional.Bundle and InstallCore (fs).<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-anti-virus-report.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-7120\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-anti-virus-report.png\" alt=\"OOO DIGITAL VEI anti-virus report\" width=\"797\" height=\"436\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-anti-virus-report.png 797w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/08\/OOO-DIGITAL-VEI-anti-virus-report-300x164.png 300w\" sizes=\"(max-width: 797px) 100vw, 797px\" \/><\/a><\/p>\n<p>Did you also find a OOO DIGITAL VEI download? What kind of download was it?<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello readers! Just a quick post on a publisher called OOO DIGITAL VEI that I found while running some tests for the upcoming FreeFixer release. The suspicious file is named adobe_flash_player.exe. Viewing the certificate information is also possible by looking under the digital signature tab for the file. Here the certificate says that OOO DIGITAL &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/ooo-digital-vei-18-detection-rate-installcore\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">OOO DIGITAL VEI &#8211; 18% Detection Rate &#8211; InstallCore<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[726,448,447,725],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7119"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=7119"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7119\/revisions"}],"predecessor-version":[{"id":7124,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/7119\/revisions\/7124"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=7119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=7119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=7119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}