FlashGuncelle.exe

Adobe

The executable FlashGuncelle.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.eklentidunyasi.com.
Publisher:
Adobe

Product:
Adobe

Version:
9

MD5:
2de9865032e997d59c03bfd8435f1ada

SHA-1:
56decf93284dc87d6e437da12eb184caaeba5357

SHA-256:
b1fe25d56a8b73f2eecbbf1ad048f260aa732b8f299da973298e9cdd226c2578

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/24/2024 6:51:09 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.77106
1128

AhnLab V3 Security
Trojan/Win32.Blocker
2014.01.01

avast!
Win32:Agent-ASJZ [Trj]
2014.9-140103

Bitdefender
Gen:Variant.Zusy.77106
1.0.20.15

Dr.Web
Trojan.DownLoader10.59063
9.0.1.03

Emsisoft Anti-Malware
Gen:Variant.Zusy.77106
8.14.01.03.02

F-Secure
Gen:Variant.Zusy.77106
11.2014-03-01_6

G Data
Gen:Variant.Zusy.77106
14.1.22

MicroWorld eScan
Gen:Variant.Zusy.77106
15.0.0.9

Panda Antivirus
Suspicious file
14.01.03.02

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
24954

File size:
191.5 KB (196,096 bytes)

Product version:
9

Copyright:
Adobe

Trademarks:
Adobe

Original file name:
FlashGuncelle.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashguncelle.exe

File PE Metadata
Compilation timestamp:
12/31/2013 8:46:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:KqypvcMfzEaLH8jG5MRXzIfYjJULqV4A1ajMLqW+B2DslviEFmMGcjHNjOzLM:8eczMjOMRXMAjJUGq7wn+xlviEFhGcjk

Entry address:
0x2D856

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6892

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
174.5 KB (178,688 bytes)

The file FlashGuncelle.exe has been seen being distributed by the following URL.

Remove FlashGuncelle.exe - Powered by Reason Core Security