flashplayer.exe

Kemeda

The executable flashplayer.exe has been detected as malware by 25 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from downloadwww32.adrive.com.
Publisher:
Kemeda  (signed and verified)

Version:
14.3.33.11

MD5:
bdda143dd09322187aa734a6d7d8a46c

SHA-1:
af29d867d8813dd9444c0238fc86bf4a48b639e2

SHA-256:
1e96af695309880dd15e288afabb095338886b9e5e81372b73311be5461075b7

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
12/27/2024 9:02:47 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2816038
393

Agnitum Outpost
Trojan.Inject
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.214049
8.3.2.2

Arcabit
Trojan.Generic.D2AF826
1.0.0.585

AVG
MSIL9
2017.0.2871

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.1617

Bitdefender
Trojan.GenericKD.2816038
1.0.20.35

Dr.Web
BackDoor.Wirenet.9
9.0.1.07

Emsisoft Anti-Malware
Trojan.GenericKD.2816038
8.16.01.07.05

ESET NOD32
MSIL/Injector.MIX (variant)
10.12481

Fortinet FortiGate
MSIL/MIX!tr
1/7/2016

F-Secure
Trojan.GenericKD.2816038
11.2016-07-01_5

G Data
Trojan.GenericKD.2816038
16.1.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.9.5.0

K7 AntiVirus
Riskware
13.212.17683

Kaspersky
Trojan.MSIL.Inject
14.0.0.851

Microsoft Security Essentials
Trojan:Win32/Dynamer!ac
1.1.12205.0

MicroWorld eScan
Trojan.GenericKD.2816038
17.0.0.21

nProtect
Trojan.GenericKD.2816038
15.10.28.01

Panda Antivirus
Trj/CI.A
16.01.07.05

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16105

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R047C0DJQ15
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
44884

File size:
321.5 KB (329,168 bytes)

Product version:
14.3.33.11

Original file name:
azure.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashplayer.exe

Digital Signature
Signed by:

Authority:
Kemeda

Valid from:
10/21/2015 7:07:25 PM

Valid to:
10/21/2016 7:07:25 PM

Subject:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Issuer:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Serial number:
008C6590B70633A028

File PE Metadata
Compilation timestamp:
10/21/2015 4:52:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:ROo4CISfEklEQ5/qsIZrISXQNrkI1lkFfOIgz+G9+K:ROo4Ch1B5/BISfrkIIF92u

Entry address:
0x514DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
317.5 KB (325,120 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security