flashplayer.exe

Blrekatar

BITT LLC

The application flashplayer.exe by BITT has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from quufafitbottomedgirls.net.
Publisher:
n sc,  (signed by BITT LLC)

Product:
Blrekatar

Description:
Mysophilia

Version:
1.00

MD5:
6d39e1a2cb3bcb95f395dbdff757c53a

SHA-1:
3f892ed69dec2881e8ccbea3a0b34b7704845106

SHA-256:
83fccb8122581f1c896a5057dc8a219ec65d82cf1e4be1f96d036735d554c052

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 11:40:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.HPDefender.BITT.Meta (M)
16.6.7.21

File size:
333.3 KB (341,272 bytes)

Product version:
1.00

Copyright:
Plaprede6

Trademarks:
Forndenheds7

Original file name:
Karikerede6.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flashplayer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/16/2016 4:00:00 PM

Valid to:
2/16/2017 3:59:59 PM

Subject:
CN="""BITT"" LLC", OU=IT, O="""BITT"" LLC", STREET="vul. Mykoly Vasylenka, 1", L=Kiev, S=Kiev, PostalCode=03113, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
01D6FE72C352595E055CDACCE2E60893

File PE Metadata
Compilation timestamp:
6/6/2016 11:01:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:475wluYMiaPVV2l6kLAYRmdtabMkMjFRUHY7:BlnM/Vy6MSdtSMjsq

Entry address:
0x1348

Entry point:
68, B8, 96, 44, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 39, 06, FB, 4C, 9F, EF, 05, 4A, 87, B9, 40, C6, 38, A1, 6F, DC, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 42, 61, 74, 69, 6B, 66, 61, 72, 76, 6E, 69, 6E, 67, 65, 6E, 38, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 04, C9, D6, E7, DF, 40, 16, 61, 4E, 91, 47, 87, 80, B2, 8A, EE, 77, 55, 63, 5A, 9E, 80, C1, 44, 4E, 92, 30, 6E, 3F, 68, 12, 95, AD, 3A, 4F, AD...
 
[+]

Entropy:
7.7453

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
316 KB (323,584 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security