flash.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from 5q9apf.ad-vid-webs.com.
MD5:
ec3db3d9e89005433d25b3a875d8c359

SHA-1:
5e0d0c599cb802e75dc95d42ddff445beff98421

SHA-256:
df49a8ab776facac78afa566d7fe7ee2b85c5ab57374cd6e561d5964ca00cb39

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 8:41:13 PM UTC  (today)

File size:
825.6 KB (845,463 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\flash.exe

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:40BOyTrAuTHukwHuNKQAuVTuL/bPAG2uZ:tOoRwIKQx0AS

Entry address:
0x30FA

Entry point:
78, 04, 88, E2, 1B, C3, 53, 77, 01, 41, 8D, 3D, 67, 61, 09, 40, 86, C8, 8A, E9, 20, FE, 80, C2, A4, 08, C9, 2B, F9, 42, F3, 0F, AF, EB, E8, 71, 00, 00, 00, 4F, 81, F7, CE, 50, A6, D8, 0F, BE, DF, 88, D3, 8D, 3D, 84, FB, 7E, BA, 38, D0, F7, C5, 57, 55, F5, BF, 81, C1, D3, D9, 0B, 00, 8D, 15, 3F, 2B, E8, A4, FF, CE, B8, A5, BC, 95, B1, 81, E9, 6D, DB, 0A, 00, 2B, FF, F2, 10, CE, 09, DB, 85, DA, F2, 2A, C5, 8B, C7, 23, CD, 81, C7, 48, FE, FF, FF, 0F, AF, C0, 0F, AF, F2, 81, C7, B9, 01, 00, 00, 1C, 83, C6, C4...
 
[+]

Code size:
23.5 KB (24,064 bytes)

The file flash.exe has been seen being distributed by the following URL.

Scan flash.exe - Powered by Reason Core Security