install_flashplayer15x32_mssa_aaa_aih.exe

The executable install_flashplayer15x32_mssa_aaa_aih.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com and multiple other hosts.
MD5:
19a817716f7fb6a7e5e39bfba5e217f3

SHA-1:
81d16243856695d6d2182cc8b8f82665f9d91360

SHA-256:
019fd253dd5ea06ea872806455031b70765370a5b303cca71b6bacd7a8bf53c7

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/24/2024 10:37:39 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Bkav FE
HW32.Paked
1.3.0.4959

IKARUS anti.virus
Trojan.Win32.Banamed
t3scan.1.7.8.0

K7 AntiVirus
Virus
13.191.14658

Kaspersky
Trojan.Win32.Banamed
14.0.0.3173

Microsoft Security Essentials
Threat.Undefined
1.191.2440.0

Norman
Krap.XK
11.20150318

Panda Antivirus
Trj/Chgt.I
14.09.30.07

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.18.1

Sophos
Virus 'W32/Patched-I'
59

VIPRE Antivirus
Threat.4726519
36694

File size:
345.5 KB (353,792 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\install_flashplayer15x32_mssa_aaa_aih.exe

File PE Metadata
Compilation timestamp:
9/29/2014 12:26:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:rzg5rS4FENUh7vVDcBJNujmGSlhlIH1DMJFeJ2EX62RCPwEFx3GhNEH:vU5Bc5ujmGsCVDQcn62RCPwEFx

Entry address:
0x1000

Entry point:
B8, DC, 1A, 52, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 2F, 9C, FE, A2, CA, 40, E3, 7E, 80, 92, 33, 4A, 51, 89, 53, 1F, C1, 5C, 48, E8, 8E, 2A, C0, 98, 84, 65, 3C, 3D, 42, D0, 1C, A5, 46, 1B, 02, 99, A6, 37, 33, 0F, 13, 4E, 07, EE, E7, AB, 40, 04, 8A, AB, E5, 0D, 57, 40, 5F, 0F, 47, 57, B9, 10, 5F, 0D, DC, C2, F1, 6A, 38, D8, C7, 84, C8, B3, 44, BD, 2C, 93, 6C, C8, E7, 86, EC, 33, 0F, 8E, B6, 8E, BB, 6C, C1, 76, FB, E1, 0F...
 
[+]

Packer / compiler:
PECompact v2

Code size:
869 KB (889,856 bytes)

The file install_flashplayer15x32_mssa_aaa_aih.exe has been seen being distributed by the following 2 URLs.

Remove install_flashplayer15x32_mssa_aaa_aih.exe - Powered by Reason Core Security