flash.exe

The executable flash.exe has been detected as malware by 37 anti-virus scanners. The program is a setup application that uses the Self-extracting archive installer, however the file is not signed with an authenticode signature from a trusted source.
MD5:
277273a994ddeb0bb676626724b0eed4

SHA-1:
273387217e3c6b07864f2a1ad7890862c4e07354

SHA-256:
1d1d4024c0ca922184f4abc4744db4246ab31b5c96496dbac16f1e1d30ce9213

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
5/10/2024 7:32:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2563481
368

Agnitum Outpost
Trojan.PWS.Fareit
7.1.1

AhnLab V3 Security
Worm/Win32.Gamarue
2015.10.03

Avira AntiVirus
TR/Crypt.Xpack.256932
8.3.2.2

Arcabit
Trojan.Generic.D271D99
1.0.0.568

avast!
Win32:Agent-AZRD [Cryp]
2014.9-160201

AVG
Crypt4
2017.0.2846

Bitdefender
Trojan.GenericKD.2563481
1.0.20.160

Bkav FE
W32.Clodced.Trojan
1.3.0.7237

Comodo Security
UnclassifiedMalware
23343

Dr.Web
BackDoor.Andromeda.614
9.0.1.032

Emsisoft Anti-Malware
Trojan.GenericKD.2563481
8.16.02.01.05

ESET NOD32
Win32/Kryptik.DPKD (variant)
10.12349

Fortinet FortiGate
W32/Fareit.BBPZ!tr.pws
2/1/2016

F-Prot
W32/Agent.XL.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.670840
11.2016-01-02_2

G Data
Trojan.GenericKD.2563481
16.2.25

IKARUS anti.virus
Trojan.Win32.Crypt
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.210.17412

Kaspersky
Trojan-PSW.Win32.Fareit
14.0.0.726

Malwarebytes
Backdoor.Bot
v2016.02.01.05

McAfee
RDN/Generic PWS.y!b2m
5600.6502

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!rfn
1.1.12101.0

MicroWorld eScan
Trojan.GenericKD.2563481
17.0.0.96

NANO AntiVirus
Trojan.Win32.Fareit.dtslik
0.30.26.3725

nProtect
Trojan.GenericKD.2563481
15.10.02.01

Panda Antivirus
Trj/Chgt.O
16.02.01.05

Qihoo 360 Security
HEUR/QVM06.2.Malware.Gen
1.0.0.1015

Quick Heal
Trojan.Skeeyah.r4
2.16.14.00

Rising Antivirus
PE:Malware.RDM.38!5.2C[F1]
23.00.65.16130

Sophos
Mal/Wonton-BB
4.98

Total Defense
Win32/Remex.ZAZB!suspicious
37.1.62.1

Trend Micro House Call
TROJ_GE.F076584B
7.2.32

Trend Micro
TROJ_GE.F076584B
10.465.01

Vba32 AntiVirus
TrojanPSW.Fareit
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
44236

ViRobot
Worm.Win32.S.Agent.335583[h]
2014.3.20.0

File size:
327.7 KB (335,583 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Self-extracting archive

Common path:
C:\users\{user}\downloads\flash.exe

File PE Metadata
Compilation timestamp:
12/2/2014 5:07:30 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:7Y20AljuB28YZgqEPfS1fE1G5NLtWOZKxXPbryxJpPikrFrcxX3vNo:7Y20AljdZgBPfKfthH6zryxPPfrRcNi

Entry address:
0x1D5DB

Entry point:
E8, 85, 63, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 82, FC, FF, FF, C7, 06, 20, B2, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, 20, B2, 42, 00, E9, 37, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 20, B2, 42, 00, E8, 24, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 4E, CA, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Code size:
161.5 KB (165,376 bytes)

Remove flash.exe - Powered by Reason Core Security