install_flashplayer15x32_mssa_aaa_aih.exe

The executable install_flashplayer15x32_mssa_aaa_aih.exe has been detected as malware by 13 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.gameplaybr.net.
MD5:
27de1054631eb079fd597c9e18b75a4c

SHA-1:
65bbcdf23e89608686a1c01e18dcf5236dd9b02a

SHA-256:
230a758d938cae9f7b8369ec0a58f09d75c51cf049d21bdf1a7b7698d444e550

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
5/17/2024 1:50:43 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.14104

Bkav FE
HW32.Paked
1.3.0.4959

ESET NOD32
Win32/TrojanDownloader.Banload.UJX (variant)
8.10508

K7 AntiVirus
Virus
13.191.14658

Kaspersky
Trojan.Win32.Banamed
14.0.0.3155

McAfee
Artemis!27DE1054631E
5600.6988

Microsoft Security Essentials
Threat.Undefined
1.191.2440.0

Norman
Krap.XK
11.20150318

Panda Antivirus
W32/Cosmu.gen
15.03.18.01

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.18.1

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Threat.4726519
36694

File size:
345.5 KB (353,792 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\install_flashplayer15x32_mssa_aaa_aih.exe

File PE Metadata
Compilation timestamp:
10/1/2014 7:12:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:9uTq4HlNuusr6pBx9yt8jtzf1uMXtu9KApJ2WCNFombwWLEmQ1fWL29Zm:YOSUm5z9uSqKApJ2WCNFoOdLTQ1M6

Entry address:
0x1000

Entry point:
B8, EC, 1A, 52, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 2F, 9C, FE, A2, CA, 40, E3, 7E, 80, 92, 33, 4A, 51, 89, 53, 1F, C1, 5C, 48, E8, 8E, 2A, C0, 98, 84, 65, 3C, 3D, 42, D0, 1C, A5, 46, 1B, 02, 99, A6, 37, 33, 0F, 13, 4E, 07, EE, E7, AB, 40, 04, 8A, AB, E5, 0D, 57, 40, 5F, 0F, 47, 57, B9, 10, 5F, 0D, DC, C2, F1, 6A, 38, D8, C7, 84, C8, B3, 44, BD, 2C, 93, 6C, C8, E7, 86, EC, 33, 0F, 8E, B6, 8E, BB, 6C, C1, 76, FB, E1, 0F...
 
[+]

Packer / compiler:
PECompact v2

Code size:
869 KB (889,856 bytes)

The file install_flashplayer15x32_mssa_aaa_aih.exe has been seen being distributed by the following URL.

Remove install_flashplayer15x32_mssa_aaa_aih.exe - Powered by Reason Core Security