flash_player_installer.exe

WindowsFormsApplication1

The executable flash_player_installer.exe has been detected as malware by 28 anti-virus scanners. The file has been seen being downloaded from flget.com and multiple other hosts.
Product:
WindowsFormsApplication1

Version:
1.0.0.0

MD5:
71f8f9a169b5f879776d455d243bdf63

SHA-1:
cbb7cde2996d9738755aa63d8b5eb1c1a184fc47

SHA-256:
a10dc671a3eb6d8dffdc1dad69d0febda9ab174ed9a72fdb5bae8523f6c534f0

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
11/27/2024 11:36:09 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8412233
352

Avira AntiVirus
TR/Drop.Chextad.A
7.11.213.58

avast!
Win32:Trojan-gen
2014.9-160218

AVG
Dropper.Small
2017.0.2830

Baidu Antivirus
Trojan.MSIL.Chextad
4.0.3.16218

Bitdefender
Trojan.Generic.8412233
1.0.20.245

Comodo Security
UnclassifiedMalware
21273

Emsisoft Anti-Malware
Trojan.Generic.8412233
8.16.02.18.10

ESET NOD32
MSIL/TrojanDropper.Small
10.11259

Fortinet FortiGate
W32/Chextad.W!tr
2/18/2016

F-Secure
Trojan.Generic.8412233
11.2016-18-02_5

G Data
Trojan.Generic.8412233
16.2.25

IKARUS anti.virus
Trojan.Win32.Webprefix
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.200.15136

Kaspersky
Trojan-Dropper.MSIL.Chextad
14.0.0.643

McAfee
Artemis!71F8F9A169B5
5600.6486

Microsoft Security Essentials
TrojanDropper:MSIL/Chextad.A
1.1.11400.0

MicroWorld eScan
Trojan.Generic.8412233
17.0.0.147

NANO AntiVirus
Trojan.Win32.Chextad.bedyms
0.30.0.296

Norman
Troj_Generic.GCZMM
11.20160218

nProtect
Trojan.Generic.8412233
15.03.03.01

Panda Antivirus
Generic Malware
16.02.18.10

Qihoo 360 Security
Malware.Radar01.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.13E3224D!333652557
23.00.65.16216

Sophos
Mal/Generic-L
4.98

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38068

Zillya! Antivirus
Dropper.Chextad.Win32.1
2.0.0.2088

File size:
18 KB (18,432 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
WindowsFormsApplication1.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flash_player_installer.exe

File PE Metadata
Compilation timestamp:
11/23/2012 10:47:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:+7LqdLuLkL+LuiCLnL4Pl9BwZgVKIdqMeQ5a0V0KgkCzYcHe+m:qOqolLSl9BwZXIdqMTaK0KgRzYcHe+m

Entry address:
0x54AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.6691

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13.5 KB (13,824 bytes)

The file flash_player_installer.exe has been seen being distributed by the following 2 URLs.

Remove flash_player_installer.exe - Powered by Reason Core Security