flashplayer.exe

Patrizias

Flop

The executable flashplayer.exe has been detected as malware by 7 anti-virus scanners. The file has been seen being downloaded from paiyafototips.com.
Publisher:
Flop

Product:
Patrizias

Description:
Aeronaut

Version:
1.00

MD5:
3599689227d1646023e16f176d7c2e13

SHA-1:
10bcc01d3a9181e6ca98833c7a8f2f0584d5ce98

SHA-256:
de7e359b83954cb7e7e6157ddf4f03ee1868d800f57015fce711cc25a0fff076

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
12/26/2024 12:19:37 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.DownLoader21.30574
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Zusy.189545
11.5.0.6191

ESET NOD32
Win32/Kovter.D trojan
8.0.319.0

F-Secure
Variant.Zusy.189545
5.15.96

Kaspersky
Trojan.Win32.Kovter
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.219.190.0

Norman
Gen:Variant.Zusy.189545
02.04.2016 17:35:19

File size:
500 KB (512,040 bytes)

Product version:
1.00

Original file name:
Linn.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\flashplayer.exe

File PE Metadata
Compilation timestamp:
4/22/2016 7:16:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:qQvm3Qv/pSt+7nLRhhYmo/owl1/A+ZjfHkvkroT0l:lm0pXh0f1PjPkisK

Entry address:
0x11B0

Entry point:
68, 90, 12, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 8A, CA, E6, 28, 7E, 1C, FB, 40, 8D, D4, A5, A6, 07, E9, 48, 0B, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 04, 00, 00, 00, 4C, 75, 6E, 6B, 61, 37, 00, 02, 00, 00, 00, 00, 07, 00, 00, 00, 1C, 31, 40, 00, 07, 00, 00, 00, D0, 30, 40, 00, 07, 00, 00, 00, 68, 30, 40, 00, 07, 00, 00, 00, 24, 30, 40, 00, 07, 00, 00, 00, DC, 2F, 40, 00, 07, 00, 00, 00, 98, 2F, 40, 00, 07, 00, 00, 00, 50, 2F, 40, 00...
 
[+]

Entropy:
5.2789

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
484 KB (495,616 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security