adobe flash player install x32-x64.exe

Sunny Player

The executable adobe flash player install x32-x64.exe has been detected as malware by 11 anti-virus scanners. The file has been seen being downloaded from siparisodemesi.com.
Publisher:
Microsoft*  (Invalid match)

Product:
Sunny Player

Version:
1.0.0.0

MD5:
57515837dbadc7932e21d5bc23f3e18f

SHA-1:
6b2ee85e925fabde4e6f34c95c7eaee2c9eb0045

SHA-256:
b0ad3a9c5e505fc797aa680d0496c421a820741f8ad36d917c2e0656bf111078

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
11/5/2024 10:30:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.490583
818

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.14118

Bitdefender
Gen:Variant.Kazy.490583
1.0.20.1560

Emsisoft Anti-Malware
Gen:Variant.Kazy.490583
8.14.11.08.02

ESET NOD32
MSIL/ExtenBro (variant)
8.10691

Fortinet FortiGate
W32/Agent.FMYX!tr
11/8/2014

F-Secure
Trojan:W32/Kilim.AG
11.2014-08-11_7

G Data
Gen:Variant.Kazy.490583
14.11.24

Kaspersky
Trojan.MSIL.Agent
14.0.0.2977

McAfee
Artemis!57515837DBAD
5600.6952

Qihoo 360 Security
Win32/Trojan.34d
1.0.0.1015

File size:
35.5 KB (36,352 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2014

Original file name:
Sunny Player.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe flash player install x32-x64.exe

File PE Metadata
Compilation timestamp:
11/8/2014 6:30:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:APR//KROvqF+q71rPhnpwY9VSTaPDMxnGF:APR//KROvxq71rP59XMxG

Entry address:
0x60CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.3147

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.5 KB (16,896 bytes)

The file adobe flash player install x32-x64.exe has been seen being distributed by the following URL.

Remove adobe flash player install x32-x64.exe - Powered by Reason Core Security