flashplayer.exe

Cotechino e lenticchie

The executable flashplayer.exe has been detected as malware by 4 anti-virus scanners. The file has been seen being downloaded from 114.ou4gsnwbt.dohtunew-3lunch.com.
Publisher:
Cotechino e lenticchie

Product:
Cotechino e lenticchie

Version:
1.02

MD5:
b7817e50752533d2db0eab63ef1fe927

SHA-1:
dc32a4dfe6c067bfd18f72f17afb086ebe0461b3

SHA-256:
cab08ff3d26f8fddaad365614dc5560fbc06e2ee1f0f81ec8cc553d4f3ba28c2

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
2/27/2025 6:39:55 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
151224-5

Dr.Web
Trojan.Kovter.118
9.0.1.05190

ESET NOD32
Win32/Kovter.D trojan
7.0.302.0

Kaspersky
Trojan.Win32.Kovter
15.0.0.562

File size:
268 KB (274,466 bytes)

Product version:
1.02

Original file name:
Cotechino e lenticchie.exe

File type:
Executable application (Win32 EXE)

Language:
Lao (Lao PDR)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\flashplayer.exe

File PE Metadata
Compilation timestamp:
1/2/2016 9:56:04 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:I4Bxbxfla+Pp1KwJiCMMVtJ3NeuDgteDz3mdo1Pokz2SzfAFZ/BRTWvHazsroIB2:ICBNfPpMwBPdeleDz2eoc2SzqvKfvoLR

Entry address:
0x109C

Entry point:
68, 98, 38, 43, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 9E, B8, E4, AE, 0E, 78, B0, 42, B7, 29, 08, B0, 8B, D7, 72, DA, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2A, 03, 38, 08, 41, 00, 46, FC, 6C, 6C, 6D, 6F, 74, 69, 76, 65, 00, 03, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 06, 3E, A5, D3, 74, 43, AA, E4, 4B, B1, EB, 7A, D4, 1F, 28, 07, A4, 7E, 42, D5, 6B, 92, EE, 09, 46, A6, B5, 29, B2, 99, 92, DB, 74, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.5355

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
256 KB (262,144 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security