updateflashplayer_425c1b51.exe

Marsukife Visatl 2010

The executable updateflashplayer_425c1b51.exe has been detected as malware by 7 anti-virus scanners.
Product:
Marsukife® Visatl 2010

Version:
6.38.6132.31732

MD5:
74b2e1e79ef9a1c9eaae46adaef789b7

SHA-1:
5f9c9a6bd70690f86499622ecd8ae3a7de6fc616

SHA-256:
c5cfcbf72c4dff503b1c21bc11afb33b1fe75444d9ba8666188a5876b6290507

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/27/2024 12:50:26 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.ZPACK.Gen2
7.11.180.138

AVG
Win32/Cryptor
2015.0.3313

ESET NOD32
Win32/Kryptik.COAW (variant)
8.10601

Malwarebytes
Trojan.FakeMS
v2014.10.22.03

McAfee
PWSZbot-FADO!74B2E1E79EF9
5600.6969

Quick Heal
FraudTool.Security
10.14.14.00

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141020

File size:
286.2 KB (293,102 bytes)

Product version:
6.38.6132.31732

Original file name:
desinko.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_425c1b51.exe

File PE Metadata
Compilation timestamp:
5/29/2011 3:18:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:3VJKAe61qzBfSV5JpjkXp/aoNUGSkiz/DQMbA+OuQAXIkz8vu6GR:FIlSV5JFkXphNizMMbA+OviIkzsVGR

Entry address:
0xCD14

Entry point:
55, 8B, EC, 81, EC, 48, 03, 00, 00, B9, 51, 00, 00, 00, 89, 8D, 3C, FD, FF, FF, 53, EB, 40, 2B, C6, 3B, 85, 68, FD, FF, FF, 74, 36, 89, 8D, A0, FD, FF, FF, 3B, 85, DC, FE, FF, FF, 75, 28, 83, F0, 13, EB, 23, 2B, C6, BE, FC, 00, 00, 00, 89, B5, 04, FD, FF, FF, 3B, 8D, 04, FE, FF, FF, 74, 0E, 83, C0, 92, 83, F9, 8A, 75, 06, 89, 85, 94, FE, FF, FF, 56, 83, E8, C4, 89, 85, 3C, FD, FF, FF, 57, 8B, 3D, F8, 4E, 43, 00, 89, 85, 3C, FD, FF, FF, 89, BD, 3C, FD, FF, FF, 83, F8, AF, 75, 06, 89, BD, 0C, FE, FF, FF, 8D...
 
[+]

Entropy:
7.8835

Developed / compiled with:
Microsoft Visual C++

Code size:
100.5 KB (102,912 bytes)

Remove updateflashplayer_425c1b51.exe - Powered by Reason Core Security