flashplayer.exe

Fork

Coders Laboratories, Inc.

The executable flashplayer.exe has been detected as malware by 11 anti-virus scanners. The file has been seen being downloaded from 956.m-tnkuu.xeihapolytechnique.com.
Publisher:
Coders Laboratories, Inc.

Product:
Fork

Version:
7.03.0001

MD5:
1ce2189f190d0df7c1585069b3fe86f2

SHA-1:
7d3c79ee54760bc840c7a1d9bdbb97da35ce6cf4

SHA-256:
811ed48bd8321381d11acc464f80b1a921d789638f15249a9e08ec16b0940b94

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
11/15/2024 12:33:42 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Jaik.9532
5813571

avast!
Win32:Malware-gen
151224-5

Dr.Web
Trojan.Kovter.118
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Jaik.9532
10.0.0.5366

ESET NOD32
Win32/Injector.CMMX trojan
7.0.302.0

Kaspersky
Trojan.Win32.VBKryjetor
15.0.0.562

McAfee
Trojan.GenericR-FCN!1CE2189F190D
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.1285.0

Norman
Gen:Variant.Jaik.9532
22.12.2015 20:50:33

Sophos
Virus 'Troj/VBInj-MJ'
5.22

VIPRE Antivirus
Threat.4150696
46150

File size:
284 KB (290,867 bytes)

Product version:
7.03.0001

Original file name:
Fork.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Traditional, Macao SAR)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\flashplayer.exe

File PE Metadata
Compilation timestamp:
11/15/2015 11:25:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:YW4t1yi+wP4XNFiQhkHxkne5xR8VIuEtIYj6JtI2U:yDN4JnexDtI4mtI/

Entry address:
0x131C

Entry point:
68, 94, 86, 43, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 81, AA, 93, 3B, 58, 9B, C1, 40, BC, BF, C1, C7, D9, D4, 8B, 28, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, C0, E3, 28, 03, 47, 61, 72, 74, 65, 6E, 64, 69, 72, 65, 6B, 74, 6F, 72, 73, 00, 00, 00, 00, 00, FF, CC, 31, 00, 01, C0, DE, 71, 3A, 3C, 47, D7, 4F, 8D, B7, 0B, EB, 84, 95, F2, 09, 52, A1, 7B, D6, 2B, 00, 3F, 4A, 8E, 52, BA, D4, 23, C6, 57, C9, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.4745

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
264 KB (270,336 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security