flashplayer.exe

Traktor crypt

The executable flashplayer.exe has been detected as malware by 9 anti-virus scanners. The file has been seen being downloaded from 466.bkacm7ddpw9j.baetiiopeningtimes.net.
Publisher:
Traktor crypt

Product:
Traktor crypt

Version:
7.02.0007

MD5:
93cc5eb0242c3e370b5662921961b448

SHA-1:
3f279fc00be452fd65f72fa4c07dcc87415b8d2f

SHA-256:
104dc1fbff3d85650b250d20e86fc9a31dfe8a5025d72ca2512bceefacc69f93

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
11/27/2024 9:22:50 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160216-3

Dr.Web
Trojan.Kovter.118
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Zusy.170670
10.0.0.5735

ESET NOD32
Win32/Kovter.D trojan
8.0.319.0

F-Prot
W32/Kovtex.A!Generic
4.6.5.141

Kaspersky
Trojan.Win32.VBKryjetor
15.0.0.562

McAfee
Trojan.Artemis!93CC5EB0242C
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.7574.0

Norman
Gen:Variant.Zusy.170670
29.02.2016 03:11:57

File size:
264 KB (270,370 bytes)

Product version:
7.02.0007

Original file name:
Traktor crypt.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\flashplayer.exe

File PE Metadata
Compilation timestamp:
11/20/2015 9:29:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:MCvrsQmqa6zhEoEz5vtZy+js2wwzmsNpR8k4OAwKg+L/pcTFulVDdYLpZi+ERBws:Mc7hq5FNfms3SyoCTFcVDWLkjwwH

Entry address:
0x14F4

Entry point:
68, C8, 3C, 43, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 7C, 2F, B0, CB, AA, 61, C5, 4B, A1, DB, CD, 45, F0, AA, 0F, 8D, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 44, 61, 63, 68, 74, 75, 72, 6D, 65, 73, 00, 00, 38, 08, 41, 00, 00, 00, 00, 00, FF, CC, 31, 00, 09, 70, 3D, 92, AA, AB, DF, 11, 41, 87, 9A, 5C, 98, 05, 14, 9E, 06, C5, F0, 2A, 41, C3, 5E, 63, 46, 9B, F8, 04, 3C, A0, A2, 8A, AF, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.5738

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
252 KB (258,048 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security