flashplayer17.exe

NOS

The executable flashplayer17.exe has been detected as malware by 27 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from downloader.disk.yandex.com.
Publisher:
NOS  (signed and verified)

Version:
17.0.0.189

MD5:
90dea499e0e04ceb63a0e2edec2ed7e9

SHA-1:
14d40cdc6de1a7678fec92794b4973198ab23668

SHA-256:
fb53acc56d68fff563faa075bc4107ba7cf8789d4dd36da4337a01c9e8415957

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/19/2024 4:13:38 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.51375
387

Agnitum Outpost
Trojan.DL.Banload
7.1.1

Avira AntiVirus
TR/Dldr.Agent.196656
8.3.1.6

Arcabit
Trojan.Strictor.DC8AF
1.0.0.425

avast!
Win32:Malware-gen
2014.9-160113

AVG
Downloader.MSIL
2017.0.2865

Baidu Antivirus
Trojan.MSIL.Banload
4.0.3.16113

Bitdefender
Gen:Variant.Strictor.51375
1.0.20.65

Comodo Security
UnclassifiedMalware
22671

Dr.Web
Trojan.DownLoad3.37774
9.0.1.013

Emsisoft Anti-Malware
Gen:Variant.Strictor.51375
8.16.01.13.04

ESET NOD32
MSIL/TrojanDownloader.Banload.DZ (variant)
10.11890

Fortinet FortiGate
MSIL/Banload.DZ!tr.dldr
1/13/2016

F-Secure
Gen:Variant.Strictor.51375
11.2016-13-01_4

G Data
Gen:Variant.Strictor.51375
16.1.25

IKARUS anti.virus
Trojan-Downloader.MSIL.Banload
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.205.16461

McAfee
RDN/PWS-Banker!dy
5600.6521

Microsoft Security Essentials
TrojanDownloader:MSIL/Limao.A
1.1.11804.0

MicroWorld eScan
Gen:Variant.Strictor.51375
17.0.0.39

NANO AntiVirus
Trojan.Win32.Agent.dtdgpr
0.30.24.2320

Panda Antivirus
Trj/Chgt.O
16.01.13.04

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R01TC0CFT15
10.465.13

VIPRE Antivirus
Trojan.Win32.Generic
41728

Zillya! Antivirus
Downloader.Banload.Win32.63840
2.0.0.2269

File size:
192 KB (196,656 bytes)

Product version:
17.0.0.189

Original file name:
stdl.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashplayer17.exe

Digital Signature
Signed by:

Authority:
NOS

Valid from:
6/20/2015 11:41:20 AM

Valid to:
6/20/2025 11:41:20 AM

Subject:
E=noreply@nos.pt, CN=www.nos.pt, O=NOS, L=Lisboa, S=Lisboa, C=PT

Issuer:
E=noreply@nos.pt, CN=www.nos.pt, O=NOS, L=Lisboa, S=Lisboa, C=PT

Serial number:
00D1546373FC3B466D

File PE Metadata
Compilation timestamp:
6/22/2015 12:24:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:mpz+Woj/pl9tFvcXpPm/nduCnQi85lo4SssssITiZJHYs:m9Nojpl9tF0XgnQiQlo4SssssIkHYs

Entry address:
0x627E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
17 KB (17,408 bytes)

The file flashplayer17.exe has been seen being distributed by the following URL.

Remove flashplayer17.exe - Powered by Reason Core Security