flashplayer11.9.exe

Win32 Cabinet Self-Extractor

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable flashplayer11.9.exe, “Win32 Cabinet Self-Extractor ” has been detected as malware by 24 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from adobeflashupdates.com.
Publisher:
Microsoft Corporation*  (Invalid match)

Product:
Microsoft® Windows® Operating System

Description:
Win32 Cabinet Self-Extractor

Version:
6.00.2900.5512 (xpsp.080413-2105)

MD5:
82572f9a1dc631a2ea2a4db3c2982c05

SHA-1:
77bb7103ee76b03674d5ab2c75a62deb96fe0bb0

SHA-256:
71854868d741609487bba7e1145ee045e3a62fdfd0ae26b06fc75fc27a2c7ad3

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/23/2024 8:26:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Trojan.GenericKDV.1367497
1137

AhnLab V3 Security
Trojan/Win32.Agent
2013.12.15

Avira AntiVirus
TR/Agent.acdiy
7.11.119.208

avast!
Win32:Malware-gen
2014.9-131224

AVG
Dropper.Generic8.CMFF.dropper
2014.0.3615

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.131224

Bitdefender
Dropped:Trojan.GenericKDV.1367497
1.0.20.1790

Comodo Security
UnclassifiedMalware
17440

Dr.Web
Trojan.PWS.Banker1.12482
9.0.1.0358

Fortinet FortiGate
W32/Agent.ACDIY!tr
12/24/2013

F-Secure
Gen:Variant.Strictor.43864
11.2013-24-12_3

G Data
Dropped:Trojan.GenericKDV.1367497
13.12.22

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.2.2.29

K7 AntiVirus
Riskware
13.174.10509

Kaspersky
Trojan.Win32.Agent
14.0.0.4571

McAfee
Artemis!82572F9A1DC6
5600.7271

MicroWorld eScan
Dropped:Trojan.GenericKDV.1367497
14.0.0.1074

Norman
Troj_Generic.RHFOC
11.20131224

Panda Antivirus
Suspicious file
13.12.24.06

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_GEN.F0C2C00KA13
7.2.358

Trend Micro
TROJ_GEN.F0C2C00KA13
10.465.24

Vba32 AntiVirus
Trojan.Agent.acdja
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
24364

File size:
1.2 MB (1,280,000 bytes)

Product version:
6.00.2900.5512

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
WEXTRACT.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\flashplayer11.9.exe

File PE Metadata
Compilation timestamp:
4/13/2008 9:32:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
24576:+PVtPyLzqnkkm+LOmV1nltVyeihQ+zUKiBOKh7JTJyn8tkz:i6UJLOmV5ltVyeF+NxKVho8tY

Entry address:
0x645C

Entry point:
E8, 0A, 00, 00, 00, E9, 7A, FF, FF, FF, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, D0, B2, 00, 01, 85, C0, 74, 07, 3D, 40, BB, 00, 00, 75, 4D, 56, 8D, 45, F8, 50, FF, 15, 70, 11, 00, 01, 8B, 75, FC, 33, 75, F8, FF, 15, 6C, 11, 00, 01, 33, F0, FF, 15, 68, 11, 00, 01, 33, F0, FF, 15, 64, 11, 00, 01, 33, F0, 8D, 45, F0, 50, FF, 15, 60, 11, 00, 01, 8B, 45, F4, 33, 45, F0, 33, C6, 25, FF, FF, 00, 00, 5E, 75, 05, B8, 40, BB, 00, 00, A3, D0, B2, 00, 01, F7, D0, A3, CC, B2, 00, 01, C9, C3, CC, CC, CC...
 
[+]

Entropy:
7.9626

Developed / compiled with:
Microsoft CAB SFX

Code size:
38.5 KB (39,424 bytes)

The file flashplayer11.9.exe has been seen being distributed by the following URL.

Remove flashplayer11.9.exe - Powered by Reason Core Security