FLVGuncelle.exe

AOE

The executable FLVGuncelle.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from commondatastorage.googleapis.com and multiple other hosts.
Publisher:
AOE

Product:
AOE

Version:
305

MD5:
11d29fc098097def85cc92e343d1f4c4

SHA-1:
32e1fd3caf83263b2cfc0ec18bb7db83ce671b79

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/24/2024 10:55:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.26338
1096

AhnLab V3 Security
Trojan/Win32.Blocker
2014.02.04

Avira AntiVirus
TR/Barys.26338.17
7.11.128.222

avast!
Win32:Ransom-ARZ [Trj]
2014.9-140203

Baidu Antivirus
Trojan.Win32.Ransomlock
4.0.3.1423

Bitdefender
Gen:Variant.Barys.26338
1.0.20.170

Comodo Security
UnclassifiedMalware
17725

Dr.Web
Trojan.Zipvideom.1
9.0.1.034

Emsisoft Anti-Malware
Gen:Variant.Barys.26338
8.14.02.03.06

ESET NOD32
MSIL/Bepush (variant)
8.9376

Fortinet FortiGate
W32/Blocker.DOYW!tr
2/3/2014

G Data
Gen:Variant.Barys.26338
14.2.24

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.2.2.29

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.4366

Malwarebytes
Trojan.Downloader.MSIL
v2014.02.03.06

McAfee
Artemis!11D29FC09809
5600.7230

MicroWorld eScan
Gen:Variant.Barys.26338
15.0.0.102

Norman
Suspicious_Gen4.FSXLT
11.20140203

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Reason Heuristics
Unnamed.Threat.61
14.3.8.9

Sophos
Mal/Generic-S
4.97

Trend Micro House Call
TROJ_GEN.R0CBB01B314
7.2.34

VIPRE Antivirus
Trojan.Win32.Generic
26106

File size:
191 KB (195,584 bytes)

Product version:
305

Copyright:
AOE

Trademarks:
AOE

Original file name:
FLVGuncelle.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\flvguncelle.exe

File PE Metadata
Compilation timestamp:
2/1/2014 1:17:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:OEEM2aWZscHEBlMDsJX+90BLTKveqc7ibD1+F55cWRg5qFnnHCd/lqEvq/Au:O8DskBKDsJffKNYF53RB9Gv

Entry address:
0x2FD0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7420

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
183.5 KB (187,904 bytes)

The file FLVGuncelle.exe has been seen being distributed by the following 2 URLs.

Remove FLVGuncelle.exe - Powered by Reason Core Security