flashplayer.exe

Blrekatar

BITT LLC

The application flashplayer.exe by BITT has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from joogawsdinsider.org.
Publisher:
n sc,  (signed by BITT LLC)

Product:
Blrekatar

Description:
Mysophilia

Version:
1.00

MD5:
1ae34dba63cb2f21a97538a2a8c60508

SHA-1:
640d675c48e44bd160d1f1b6c7a945dd0a64a25c

SHA-256:
34eb991c6a8822794dc616e9ffd0ac741fb5c3dfedd4ce3b24de24b52a4db5cc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/11/2024 11:37:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.HPDefender (M)
17.1.23.20

File size:
333.3 KB (341,280 bytes)

Product version:
1.00

Copyright:
Plaprede6

Trademarks:
Forndenheds7

Original file name:
Karikerede6.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flashplayer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/16/2016 7:00:00 PM

Valid to:
2/16/2017 6:59:59 PM

Subject:
CN="""BITT"" LLC", OU=IT, O="""BITT"" LLC", STREET="vul. Mykoly Vasylenka, 1", L=Kiev, S=Kiev, PostalCode=03113, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
01D6FE72C352595E055CDACCE2E60893

File PE Metadata
Compilation timestamp:
6/6/2016 2:01:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1348

Entry point:
68, B8, 96, 44, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 39, 06, FB, 4C, 9F, EF, 05, 4A, 87, B9, 40, C6, 38, A1, 6F, DC, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 42, 61, 74, 69, 6B, 66, 61, 72, 76, 6E, 69, 6E, 67, 65, 6E, 38, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 04, C9, D6, E7, DF, 40, 16, 61, 4E, 91, 47, 87, 80, B2, 8A, EE, 77, 55, 63, 5A, 9E, 80, C1, 44, 4E, 92, 30, 6E, 3F, 68, 12, 95, AD, 3A, 4F, AD...
 
[+]

Entropy:
7.7452

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
316 KB (323,584 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

https://joogawsdinsider.org/8491756371735/8491756371735/.../FlashPlayer.exe

Remove flashplayer.exe - Powered by Reason Core Security