install_flashplayer11x32_aih_wnw.exe

The executable install_flashplayer11x32_aih_wnw.exe has been detected as malware by 28 anti-virus scanners. The file has been seen being downloaded from observatorio.esportes.mg.gov.br.
MD5:
4753e90b7d3ddecce5b377ee1314baef

SHA-1:
71264f2d6d65ade5aff955789e87185c96988460

SHA-256:
93322de267a4d02433163ae998310fef1607f79c386bc49f504ccd11d8944bbe

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/20/2024 12:26:19 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Vobfus
2013.10.28

Avira AntiVirus
TR/Graftor.50132.66
7.11.109.178

avast!
Win32:Delf-TLT [Trj]
2014.9-131126

AVG
Generic34
2014.0.3643

Baidu Antivirus
Trojan.Win32.Downloader
4.0.3.131126

Bitdefender
Gen:Variant.Graftor.50132
1.0.20.1175

Comodo Security
UnclassifiedMalware
17167

Emsisoft Anti-Malware
Gen:Variant.Zusy.63483
8.13.08.23.04

ESET NOD32
Win32/TrojanDownloader.Banload.SKN
7.8973

Fortinet FortiGate
W32/Vobfus.VNY!tr
8/23/2013

F-Secure
Gen:Variant.Zusy.63483
11.2013-26-11_3

G Data
Gen:Variant.Zusy.63483
13.8.22

IKARUS anti.virus
Trojan.Win32.Vobfus
t3scan.2.0.127

K7 AntiVirus
Trojan
13.173.9994

Kaspersky
Trojan.Win32.Vobfus
14.0.0.3766

Malwarebytes
Trojan.Delf.3m
v2013.11.26.12

McAfee
RDN/PWS-Banker.dldr!g
5600.7176

Microsoft Security Essentials
Trojan:Win32/Dynamer!dtc
1.163.1557.3

MicroWorld eScan
Gen:Variant.Zusy.63483
14.0.0.705

NANO AntiVirus
Trojan.Win32.Delf.cwxnz
0.26.0.55532

Norman
Downloader.HIXP
11.20131126

Panda Antivirus
Generic Malware
13.11.26.12

Quick Heal
Trojan.Dynamer
11.13.12.00

Reason Heuristics
Unnamed.Threat.65
14.3.1.0

Rising Antivirus
Worm.Win32.VBInjectEx.a
23.00.65.13821

Sophos
Mal/Generic-S
4.94

VIPRE Antivirus
Trojan.Win32.Generic
22780

ViRobot
Trojan.Win32.A.Vobfus.499200
2011.4.7.4223

File size:
487.5 KB (499,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\install_flashplayer11x32_aih_wnw.exe

File PE Metadata
Compilation timestamp:
8/22/2013 11:31:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:6XSGh6kFyHeFFGC7cS/puzqyJ3nmdR1kfgjdlA:6tckQeFFGCo+mqg3nmYgjU

Entry address:
0x58724

Entry point:
55, 8B, EC, 83, C4, F0, B8, 08, 7D, 45, 00, E8, EC, DE, FA, FF, A1, B0, A9, 45, 00, 8B, 00, E8, E8, C4, FF, FF, A1, B0, A9, 45, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, 9C, AA, 45, 00, A1, B0, A9, 45, 00, 8B, 00, 8B, 15, 84, 6B, 45, 00, E8, DD, C4, FF, FF, A1, B0, A9, 45, 00, 8B, 00, E8, 09, C6, FF, FF, E8, 00, C0, FA, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.8216

Developed / compiled with:
Microsoft Visual C++

Code size:
350 KB (358,400 bytes)

The file install_flashplayer11x32_aih_wnw.exe has been seen being distributed by the following URL.

Remove install_flashplayer11x32_aih_wnw.exe - Powered by Reason Core Security