instalador_flashplayer13x32_mssd_aax.exe

The executable instalador_flashplayer13x32_mssd_aax.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from my.bitcasa.com.
MD5:
c789e3f5d7d346193b173207b13f9199

SHA-1:
f0a265bc96410f583f61e49f69ad0ada38087ec6

SHA-256:
b4d5c4fa1626f363c6214dda0d26960527357f33111da8f0b2ae3864e18ed161

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
5/2/2024 3:14:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.BGW@Y!V2Aai
256

Avira AntiVirus
TR/Spy.454144.25
7.11.127.78

avast!
Win32:Zbot-RXH [Trj]
2014.9-160524

AVG
Zbot
2017.0.2734

Baidu Antivirus
Trojan.Win32.Delf
4.0.3.16524

Bitdefender
Gen:Trojan.Heur.BGW@Y!V2Aai
1.0.20.725

Comodo Security
UnclassifiedMalware
17682

Emsisoft Anti-Malware
Gen:Trojan.Heur.BGW@Y!V2Aai
8.16.05.24.06

ESET NOD32
Win32/TrojanDownloader.Delf.AFL (variant)
10.9341

Fortinet FortiGate
W32/PWSZbot_FFY.C789E3F5D7D3!tr
5/24/2016

F-Secure
Gen:Trojan.Heur.BGW@Y!V2Aai
11.2016-24-05_3

G Data
Gen:Trojan.Heur.BGW@Y!V2Aai
16.5.24

IKARUS anti.virus
Backdoor.Win32.Yobdam
t3scan.2.2.29

K7 AntiVirus
Trojan-Downloader
13.175.10963

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.164

McAfee
PWSZbot-FFY!C789E3F5D7D3
5600.6390

MicroWorld eScan
Gen:Trojan.Heur.BGW@Y!V2Aai
17.0.0.435

NANO AntiVirus
Trojan.Win32.BotFFY.chfjel
0.28.0.57380

Norman
Downloader
11.20160524

Panda Antivirus
Trj/CI.A
16.05.24.06

Qihoo 360 Security
Win32/Trojan.b77
1.0.0.1015

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
9124

Trend Micro House Call
TROJ_GEN.R0CBC0PJ313
7.2.145

Trend Micro
TROJ_GEN.R0CBC0PJ313
10.465.24

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Banload.sse
25854

File size:
443.5 KB (454,144 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:GQ3aHVOljrqwcgjI/SLsJ5Z5/3L26ZrzPJnYzEj3vCPQ6UpLUBLruevhkvel:ZaHVOlPjI/fJ5vnrFnYzKZUB3uJ8

Entry address:
0x5E3AC

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, B8, 3C, E0, 45, 00, E8, D5, 7C, FA, FF, 33, C0, 55, 68, B8, E4, 45, 00, 64, FF, 30, 64, 89, 20, 6A, 40, 8D, 4D, EC, BA, D0, E4, 45, 00, B8, E0, E4, 45, 00, E8, 47, FB, FF, FF, 8B, 45, EC, E8, EF, 5F, FA, FF, 50, 8D, 4D, E8, BA, D0, E4, 45, 00, B8, F0, E4, 45, 00, E8, 2C, FB, FF, FF, 8B, 45, E8, E8, D4, 5F, FA, FF, 50, 6A, 00, E8, 78, 85, FA, FF, 48, 0F, 85, 82, 00, 00, 00, 8D, 4D, E4, BA, D0, E4, 45, 00, B8, 10, E5, 45, 00, E8, 03, FB, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
373.5 KB (382,464 bytes)

The file instalador_flashplayer13x32_mssd_aax.exe has been seen being distributed by the following URL.

Remove instalador_flashplayer13x32_mssd_aax.exe - Powered by Reason Core Security