flashplayer.exe

Steremon

Steremon Vendor, Inc.

The executable flashplayer.exe has been detected as malware by 8 anti-virus scanners. The file has been seen being downloaded from 302.uk4klfblti.kieriwinpalace.net.
Publisher:
Steremon Vendor, Inc.

Product:
Steremon

Version:
3.01.0001

MD5:
9b7b2817ea8c9247c93475f99fd89907

SHA-1:
e4d1f697481c4abfde328fa8c11f37414cedeab8

SHA-256:
d0acee96e484a120861c84f2296e93f76c29d14c908fa87a953917d6ac566eb8

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
11/24/2024 3:29:27 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Trojan-gen
160108-0

Dr.Web
Trojan.Kovter.118
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Zusy.175341
10.0.0.5366

ESET NOD32
Win32/Kovter.D trojan
7.0.302.0

F-Secure
Gen:Variant.Zusy.175341
5.15.21

Kaspersky
Trojan.Win32.Kovter
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.213.2188.0

Norman
Gen:Variant.Zusy.175341
17.12.2015 06:34:11

File size:
268 KB (274,474 bytes)

Product version:
3.01.0001

Original file name:
Steremon.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashplayer.exe

File PE Metadata
Compilation timestamp:
1/5/2016 7:34:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:t1EL2HcrXZBDG72GiXfsXNlozDpCPtptUxNLdzgK7MN4IsZS4MrT2K3a1yXvcYd8:t1g2HCDGic9ksTkbzgK7z302cVvij

Entry address:
0x124C

Entry point:
68, 7C, 6B, 43, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 02, DE, 9E, C2, 9C, 4A, 70, 4E, A2, 2E, CC, 4F, 5E, DC, FC, 16, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 42, 00, 06, 50, 83, 01, 4B, 69, 6E, 64, 65, 72, 62, FC, 68, 6E, 65, 00, 44, B2, 1F, 03, 00, 00, 00, 00, FF, CC, 31, 00, 02, F1, 00, 20, C6, 4A, 22, 35, 4A, B3, E3, C0, 33, 91, 7A, 3C, 62, 99, E9, A4, E8, B2, AD, DA, 47, 85, 68, 68, CA, F6, C2, D9, 0E, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.5786

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
256 KB (262,144 bytes)

The file flashplayer.exe has been seen being distributed by the following URL.

Remove flashplayer.exe - Powered by Reason Core Security