FlashGuncelle.exe

Adobe

The executable FlashGuncelle.exe has been detected as malware by 27 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.eklentidunyasi.com and multiple other hosts.
Publisher:
Adobe

Product:
Adobe

Version:
7

MD5:
61f5af5d0067ea8d10f0764ff3c82066

SHA-1:
0a1d9430c88010b484cf015b0b105980a811573e

SHA-256:
e4f6ca49860fa65612de3249e506367f3ed7935bc747064c6b0550959372c8bc

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/25/2024 6:41:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.77106
1136

AhnLab V3 Security
Trojan/Win32.Blocker
2014.01.06

Avira AntiVirus
TR/Strictor.23182.30
7.11.123.152

avast!
Win32:Agent-ASJZ [Trj]
2014.9-131225

AVG
Generic35
2014.0.3614

Baidu Antivirus
Trojan.Win32.Ransomlock
4.0.3.131225

Bitdefender
Gen:Variant.Zusy.77106
1.0.20.1795

Bkav FE
W32.Corulip.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17558

Dr.Web
Trojan.DownLoader10.59063
9.0.1.0359

Emsisoft Anti-Malware
Gen:Variant.Zusy.77106
8.13.12.25.06

Fortinet FortiGate
W32/Blocker.DBTS!tr
12/25/2013

F-Secure
Gen:Variant.Zusy.77106
11.2013-25-12_4

G Data
Gen:Variant.Zusy.77106
13.12.22

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10735

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.4566

Malwarebytes
Trojan.MSIL
v2014.01.20.07

McAfee
Artemis!61F5AF5D0067
5600.7270

MicroWorld eScan
Gen:Variant.Zusy.77106
14.0.0.1077

Norman
Suspicious_Gen4.FMTFI
11.20131225

Panda Antivirus
Trj/CI.A
13.12.25.06

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_GEN.R0CBC0OLH13
7.2.359

Trend Micro
TROJ_GEN.R0CBC0OLH13
10.465.25

Vba32 AntiVirus
Hoax.Blocker
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
25114

File size:
191.5 KB (196,096 bytes)

Product version:
7

Copyright:
Adobe

Trademarks:
Adobe

Original file name:
FlashGuncelle.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\flashguncelle.exe

File PE Metadata
Compilation timestamp:
12/11/2013 8:19:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:MqOXRvcMfQOyJTyPk5t34RavY6b3s2OjL/6U6y3HvCAOfDiLe:WX2cQO4TyWtqavVOf/6M6H

Entry address:
0x2D82E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6882

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
174.5 KB (178,688 bytes)

The file FlashGuncelle.exe has been seen being distributed by the following 2 URLs.

Remove FlashGuncelle.exe - Powered by Reason Core Security