flashmaker.exe

DylAXlMsbbFe

The executable flashmaker.exe has been detected as malware by 26 anti-virus scanners. The file has been seen being downloaded from watchsvideos.googlecode.com and multiple other hosts.
Product:
DylAXlMsbbFe

Version:
1.0.0.0

MD5:
ced88adf5963d81d24263185d49dd136

SHA-1:
63c3e844bac56bf4fe19d09ec4b439c43cd0006a

SHA-256:
b35b3930911941c21be153c65526d6bf257e9447b3347ab9cb73c0d1daf985dd

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/25/2024 4:53:32 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1635976
1026

Agnitum Outpost
Trojan.Injector
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.142.186

avast!
Win32:Rootkit-gen [Rtk]
2014.9-140414

AVG
MSIL2
2015.0.3504

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.14414

Bitdefender
Trojan.GenericKD.1635976
1.0.20.520

Emsisoft Anti-Malware
Trojan.GenericKD.1635976
8.14.04.14.03

ESET NOD32
MSIL/Injector.DIH (variant)
8.9665

Fortinet FortiGate
W32/Fsysna.DHJ!tr
4/14/2014

F-Secure
Trojan.GenericKD.1635976
11.2014-14-04_2

G Data
Trojan.GenericKD.1635976
14.4.24

IKARUS anti.virus
Trojan.Win32.Kilim
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11721

Kaspersky
Trojan.Win32.Fsysna
14.0.0.4017

McAfee
Artemis!CED88ADF5963
5600.7160

Microsoft Security Essentials
Trojan:Win32/Kilim.J
1.10401

MicroWorld eScan
Trojan.GenericKD.1635976
15.0.0.312

Norman
Suspicious_Gen4.GDJCY
11.20140414

nProtect
Trojan.GenericKD.1635976
14.04.11.01

Panda Antivirus
Trj/CI.A
14.04.14.03

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0DDA14
7.2.104

Trend Micro
TROJ_GEN.R0CBC0DDA14
10.465.14

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28194

File size:
875.9 KB (896,889 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
cq1.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashmaker.exe

File PE Metadata
Compilation timestamp:
4/6/2014 9:24:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:ElM5JrTPz5C777+cPzlaHxDRcEiP/3IWVJ/0cijf:ElSjY7775oo/4

Entry address:
0x487AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5263

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
284 KB (290,816 bytes)

The file flashmaker.exe has been seen being distributed by the following 2 URLs.

https://watchsvideos.googlecode.com/.../FlashMaker.exe

Remove flashmaker.exe - Powered by Reason Core Security