installer_adobe_flash_player_arabe.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from rosoz74663puru.kilakrenazu.info.
MD5:
3dcddd8982a1ff0df82eed20c50c878e

SHA-1:
248440dbbc08b6933fd365db9d886fe459c3cf82

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/16/2025 9:24:13 AM UTC  (today)

File size:
1.1 MB (1,132,872 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\documents and settings\dell\mes documents\downloads\installer_adobe_flash_player_arabe.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:h22fgKZSmlDWT2CRkXv+mRjKSVFcriCCevZCvM0iia5p+xF+Y7FyA:nIKZSZT2OkXvRjbVqri1ACvM0HypXA

Entry address:
0x30FA

Entry point:
60, C6, C2, E7, 68, 82, 2E, F5, 00, 51, 85, D3, C6, C7, 85, 68, 7A, DA, 25, 00, 55, 81, D1, AA, 31, E5, 13, 4D, 0F, B6, D3, F7, C1, 0C, A9, B1, 25, 88, E1, E8, 49, 00, 00, 00, 81, FA, FB, E1, 00, 00, 70, 09, F6, C0, F1, 8D, 35, 42, 5F, 3F, 84, 0F, B6, F3, 8B, C7, 84, C2, EB, 04, 84, EF, 86, DC, 69, E8, 66, 7C, 94, 04, FF, C8, 8B, F1, BA, 89, A6, 00, 00, 8D, 0D, E3, 10, 3D, 28, 0F, AF, C1, EB, 03, 80, E5, 2F, 2B, FA, 8D, 1D, 83, 92, 59, 2B, 8D, 0D, 38, BF, 39, 5A, 58, B9, CE, 3D, 6F, 87, 0F, AF, F3, 0F, BF...
 
[+]

Code size:
23.5 KB (24,064 bytes)

The file installer_adobe_flash_player_arabe.exe has been seen being distributed by the following URL.

Scan installer_adobe_flash_player_arabe.exe - Powered by Reason Core Security