flashplayer.exe

Flowers Grow

Flowers Grow Technologies Inc.

Publisher:
Flowers Grow Technologies Inc.

Product:
Flowers Grow

Version:
7.08.0008

MD5:
67759f20426bd13bddc032d2ad61d193

SHA-1:
5ec64448fd5f537f3a5ee32f88b08c0c3cd0447f

SHA-256:
74b257dbd8ba41e25b99df25ddb8380a0e43cc65ec45f5a9bca926668f255a10

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/3/2024 3:38:49 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Injector.CQSN trojan
6.3

File size:
410.1 KB (419,982 bytes)

Product version:
7.08.0008

Original file name:
Flowers Grow.exe

File type:
Executable application (Win32 EXE)

Language:
Bulgarian (Bulgaria)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\flashplayer.exe

File PE Metadata
Compilation timestamp:
1/22/2016 2:05:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:zNGGkikGGxi7QxetknGZ58KJu5BMBP8TblHQYpntp+Cw84XJ164sUx:zNGGkBGGYkItAsO5BnVQytJID/x

Entry address:
0x1218

Entry point:
68, 74, 92, 44, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, B5, 42, F7, 04, 8E, E8, 9F, 4C, 8B, 34, 7A, 16, C2, B1, 45, C9, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, B9, B9, B9, B9, B9, 6C, 46, 6C, 6F, 63, 6B, 65, 6E, 73, 74, 72, 75, 6B, 74, 75, 72, 65, 6E, 00, B9, 92, B9, B9, 30, 15, 00, 00, 00, 00, FF, CC, 31, 00, 03, E7, FA, 9E, A0, E5, 42, 8C, 4E, B9, CC, 3C, 6F, 50, 70, 98, DB, E8, 83, F4, 41, E9, B0, 23, 49, 9B, 87, 9B, A1, 6D, 28, 1C, D4, 3A, 4F, AD...
 
[+]

Entropy:
7.0965

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
372 KB (380,928 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Scan flashplayer.exe - Powered by Reason Core Security