flashbeat.exe

FlashBeat

The application flashbeat.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named XOUMZGZXV1 triggered to execute each time a user logs in. While running, it connects to the Internet address server-54-230-71-10.sea50.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
FlashBeat

Product:
FlashBeat

Description:
Application

Version:
0, 12, 2072, 0

MD5:
a564f040a7c0abd0aea83eb833f5f1fc

SHA-1:
a428bf22cdf5084a955d217624147393b1b32506

SHA-256:
a1a01fd606287a53e4148d28e85efa6a0a03cd9764bd12ba6c012b1e66ff23c4

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:20:21 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
AdWare.Couponmarvel
t3scan.1.9.5.0

Malwarebytes
PUP.Optional.FlashBeat
v2015.08.29.06

Reason Heuristics
PUP.LolliScan.FlashBeat.Meta (M)
15.8.29.18

VIPRE Antivirus
FlashBeat
43258

File size:
768.5 KB (786,944 bytes)

Product version:
2, 0, 0, 0

Copyright:
Copyright (C) 2015

Original file name:
FlashBeat

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\flashbeat\flashbeat.exe

File PE Metadata
Compilation timestamp:
8/27/2015 12:52:18 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:n4/KFW10zA+wAIcbNAPV7PYDjf8sEp1qFA:SwnlbkeQL

Entry address:
0x5E2F4

Entry point:
48, 83, EC, 28, E8, 77, 7E, 00, 00, 48, 83, C4, 28, E9, 02, 00, 00, 00, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 30, E8, 30, 54, 00, 00, 0F, B7, F0, B9, 02, 00, 00, 00, E8, 03, 7E, 00, 00, B8, 4D, 5A, 00, 00, 48, 8D, 3D, CB, 1C, FA, FF, 66, 39, 05, C4, 1C, FA, FF, 74, 04, 33, DB, EB, 31, 48, 63, 05, F3, 1C, FA, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 75, EA, B9, 0B, 02, 00, 00, 66, 39, 48, 18, 75, DF, 33, DB, 83, B8, 84, 00, 00, 00, 0E, 76, 09, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89...
 
[+]

Entropy:
6.0447

Code size:
532.5 KB (545,280 bytes)

Scheduled Task
Task name:
XOUMZGZXV1

Trigger:
Logon (Runs on logon)


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-71-10.sea50.r.cloudfront.net  (54.230.71.10:80)

TCP (HTTP):
Connects to li1076-210.members.linode.com  (45.33.93.210:80)

TCP (HTTP SSL):
Connects to ec2-54-68-135-85.us-west-2.compute.amazonaws.com  (54.68.135.85:443)

Remove flashbeat.exe - Powered by Reason Core Security