chromium_flash.x86_32.exe

The executable chromium_flash.x86_32.exe has been detected as malware by 25 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from kingcdn.googlecode.com and multiple other hosts.
MD5:
606096f7b9356efc77adc63002bd120d

SHA-1:
312a47b6787d86a8b52d864a73e434330380bb16

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/24/2024 9:22:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.137719
1011

Agnitum Outpost
Trojan.DL.VB
7.1.1

Avira AntiVirus
TR/Dldr.VB.QLO
7.11.145.10

avast!
Win32:VB-AHYI [Trj]
2014.9-140430

AVG
Downloader.VB
2015.0.3489

Baidu Antivirus
Trojan.Win32.VB
4.0.3.14430

Bitdefender
Gen:Variant.Graftor.137719
1.0.20.600

Emsisoft Anti-Malware
Gen:Variant.Graftor.137719
8.14.04.30.03

ESET NOD32
Win32/TrojanDownloader.VB.QLO (variant)
8.9714

Fortinet FortiGate
W32/VB.QLO!tr.dldr
4/30/2014

F-Secure
Gen:Variant.Graftor.137719
11.2014-30-04_4

G Data
Gen:Variant.Graftor.137719
14.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

K7 AntiVirus
Trojan-Downloader
13.176.11861

Kaspersky
Trojan-Downloader.Win32.VB
14.0.0.3939

Malwarebytes
Trojan.FakeAdobe
v2014.04.30.03

McAfee
RDN/Generic Downloader.x!kb
5600.7145

MicroWorld eScan
Gen:Variant.Graftor.137719
15.0.0.360

NANO AntiVirus
Trojan.Win32.VB.cwnemy
0.28.0.59492

Norman
VBTroj.UWDG
11.20140430

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_FAKEADO.A
7.2.120

Trend Micro
TROJ_FAKEADO.A
10.465.30

VIPRE Antivirus
Trojan.Win32.Generic
28550

File size:
510.5 KB (522,791 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\user\belgelerim\downloads\chromium_flash.x86_32.exe

File PE Metadata
Compilation timestamp:
12/1/2013 10:08:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:0RWNcr8oxnTHkoOl/Op2Nc71tSoRUMdlA3U8aPx:PNBITUlhW7XH7dChaPx

Entry address:
0x1D728

Entry point:
E8, F0, 57, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 05, FD, FF, FF, C7, 06, E4, 81, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, E4, 81, 42, 00, E9, BA, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, E4, 81, 42, 00, E8, A7, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, D1, C9, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Code size:
149.5 KB (153,088 bytes)

The file chromium_flash.x86_32.exe has been seen being distributed by the following 2 URLs.

Remove chromium_flash.x86_32.exe - Powered by Reason Core Security