FlashGuncelle.exe

Adobe

The executable FlashGuncelle.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0g-4o-docs.googleusercontent.com and multiple other hosts.
Publisher:
Adobe

Product:
Adobe

Version:
6

MD5:
25234e3889fd68fbcc4b48aa746b08c1

SHA-1:
33a32ce72cb7ea7bd4641f17f6d7b59abdf0c0fc

SHA-256:
1e032f180fd4433295517fb41415533f027ba097ba847d8c8811e18e9be41c60

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/19/2024 1:07:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.77106
1133

Agnitum Outpost
Trojan.Blocker
7.1.1

AhnLab V3 Security
Trojan/Win32.Blocker
2014.01.01

Avira AntiVirus
TR/Strictor.23182.33
7.11.122.208

avast!
Win32:Agent-ASJZ [Trj]
2014.9-131228

AVG
Generic35
2014.0.3611

Baidu Antivirus
Trojan.Win32.Ransomlock
4.0.3.131228

Bitdefender
Gen:Variant.Zusy.77106
1.0.20.1810

Bkav FE
W32.Clod49e.Trojan
1.3.0.4613

Dr.Web
Trojan.DownLoader10.59063
9.0.1.0362

Emsisoft Anti-Malware
Gen:Variant.Zusy.77106
8.13.12.28.09

Fortinet FortiGate
W32/Blocker.DBTN!tr
12/28/2013

F-Secure
Gen:Variant.Zusy.77106
11.2013-28-12_7

G Data
Gen:Variant.Zusy.77106
13.12.22

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10689

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.4551

Malwarebytes
Trojan.MSIL
v2014.01.12.01

McAfee
Artemis!25234E3889FD
5600.7267

MicroWorld eScan
Gen:Variant.Zusy.77106
14.0.0.1086

Norman
Suspicious_Gen4.FMVLS
11.20131228

Panda Antivirus
Trj/CI.A
14.01.12.01

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_RANSOM.JKK
7.2.362

Trend Micro
TROJ_RANSOM.JKK
10.465.28

VIPRE Antivirus
Trojan.Win32.Generic
24946

File size:
191.5 KB (196,096 bytes)

Product version:
6

Copyright:
Adobe

Trademarks:
Adobe

Original file name:
FlashGuncelle.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashguncelle.exe

File PE Metadata
Compilation timestamp:
12/11/2013 7:18:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:CsqdNsvcMfj07KJ+nEgYrq4qwlO2DsQFTjoiik01gLfOSWX49Wqv2wIYBOP5cVVt:C1N/cj0O8EHrkwIKsQFT8iiMWLEWqvP5

Entry address:
0x2D826

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6887

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
174.5 KB (178,688 bytes)

The file FlashGuncelle.exe has been seen being distributed by the following 8 URLs.

Remove FlashGuncelle.exe - Powered by Reason Core Security