flashplayer13.exe

The executable flashplayer13.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
MD5:
eaf0759292625c9f11a35da3f194e588

SHA-1:
3bf395f45d8b1f07092f90f22e4a7c22d078a21e

SHA-256:
ee41983b6df952fd892ffcb64b69af0fdb9c250e347ea88084d186f0f2ae8ec5

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/24/2024 11:21:01 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DownLoader
7.1.1

AhnLab V3 Security
Trojan/Win32.Agent
2015.04.04

avast!
Win32:Dropper-gen [Drp]
2014.9-150404

Bitdefender
Trojan.Generic.13149013
1.0.20.945

Comodo Security
UnclassifiedMalware
21644

Dr.Web
Trojan.DownLoader12.51038
9.0.1.094

Emsisoft Anti-Malware
Trojan-Dropper.Python.Agent
8.15.04.04.04

ESET NOD32
Python/FBook
9.11424

Fortinet FortiGate
Python/FBook.B!tr
4/4/2015

G Data
Win32.Trojan.Agent.FR0X5F
15.4.25

herdProtect (fuzzy)
2015.7.8.23

IKARUS anti.virus
Trojan.Python.Fbook
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15658

Kaspersky
Trojan-Downloader.Python.Agent
14.0.0.2241

Malwarebytes
Trojan.Facebook
v2015.04.04.04

McAfee
Artemis!EE995A3D703F
5600.6805

MicroWorld eScan
Trojan.Generic.13149013
16.0.0.567

Norman
Suspicious_Gen4.IEQXI
11.20150404

nProtect
Trojan.Generic.13149013
15.04.20.01

Panda Antivirus
Generic Suspicious
15.04.04.04

Trend Micro House Call
TROJ_GEN.R08NC0EDD15
7.2.94

Trend Micro
TROJ_GEN.R00GC0ED115
10.465.04

VIPRE Antivirus
Trojan.Win32.Generic
39046

File size:
6 MB (6,296,193 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\flashplayer13.exe

File PE Metadata
Compilation timestamp:
3/23/2013 6:26:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:E2tCKwgTbsysEvEQWARzlgV0EscAbbpSzZTfu:PkKZTbsnXAmNsMzZf

Entry address:
0xB223

Entry point:
E8, 2C, 8E, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, 53, 57, 33, FF, 8B, 44, 24, 10, 0B, C0, 7D, 14, 47, 8B, 54, 24, 0C, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 10, 89, 54, 24, 0C, 8B, 44, 24, 18, 0B, C0, 7D, 13, 8B, 54, 24, 14, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 18, 89, 54, 24, 14, 0B, C0, 75, 1B, 8B, 4C, 24, 14, 8B, 44, 24, 10, 33, D2, F7, F1, 8B, 44, 24, 0C, F7, F1, 8B, C2, 33, D2, 4F, 79, 4E, EB, 53, 8B, D8, 8B, 4C, 24, 14, 8B, 54, 24, 10, 8B, 44, 24, 0C, D1, EB, D1, D9, D1, EA, D1, D8, 0B, DB, 75...
 
[+]

Entropy:
7.9825  (probably packed)

Code size:
105.5 KB (108,032 bytes)

The file flashplayer13.exe has been seen being distributed by the following URL.

Remove flashplayer13.exe - Powered by Reason Core Security