adobe flash player.exe

mscfg32a

PrivSoft Systems

The executable adobe flash player.exe has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
Publisher:
PrivSoft Systems

Product:
mscfg32a

Version:
1.00

MD5:
07c2467af0e63f745eaf187cdc207a0d

SHA-1:
2a63c9164d019e8b521bbe3b57625d5b847246ba

SHA-256:
c3e6701d8017f14083bdd4c80a9bfc6bb561e4a16dc996d8d94f1ef888d26546

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
4/24/2024 2:24:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.144719
606

avast!
Win32:Malware-gen
2014.9-150609

AVG
Generic36
2016.0.3084

Bitdefender
Gen:Variant.Graftor.144719
1.0.20.800

Emsisoft Anti-Malware
Gen:Variant.Graftor.144719
8.15.06.09.02

ESET NOD32
probably unknown NewHeur_PE
9.11586

Fortinet FortiGate
W32/VB.ZIL!tr.dldr
6/9/2015

F-Secure
Gen:Variant.Graftor.144719
11.2015-09-06_3

G Data
Gen:Variant.Graftor.144719
15.6.25

K7 AntiVirus
Trojan
13.203.15826

Kaspersky
Trojan-Downloader.Win32.Genome
14.0.0.1915

McAfee
Artemis!07C2467AF0E6
5600.6740

MicroWorld eScan
Gen:Variant.Graftor.144719
16.0.0.480

Panda Antivirus
Trj/CI.A
15.06.09.02

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R047H09E615
7.2.160

File size:
20 KB (20,480 bytes)

Product version:
1.00

Original file name:
mscfg32a.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\adobe flash player.exe

File PE Metadata
Compilation timestamp:
5/5/2015 8:09:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:GddDRLxUWuyTx7f/ZYF2X0dINhe+kDw55S:0dDXUWZTx7Cx+k

Entry address:
0x12BC

Entry point:
68, 18, 14, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 31, EE, 45, CF, 1A, 63, 8E, 45, 83, 35, D4, 5D, CE, 8C, 44, E6, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 56, 62, 6D, 73, 63, 66, 67, 33, 32, 61, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 00, 6E, AD, 60, 9F, C1, 18, F6, 48, AC, FF, D6, 6D, 04, 9E, CC, 75, 62, E7, 26, 77, C5, 0F, E1, 40, AB, 0B, DC, 35, D7, 51, 64, 7D, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
8 KB (8,192 bytes)

The file adobe flash player.exe has been seen being distributed by the following URL.

Remove adobe flash player.exe - Powered by Reason Core Security