flashplayer16.exe

The application flashplayer16.exe has been detected as a potentially unwanted program by 24 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.parademinas.mg.gov.br and multiple other hosts.
MD5:
0a7302b7bbff48e02fdf04b5c1ae9926

SHA-1:
b6404276ef90ff5d8037fdfd600ceba1e292e543

SHA-256:
a6db1db410695b28df87fe6d70797a6d61962c5c22df96ca374c0f15847e876e

Scanner detections:
24 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 7:45:18 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.45916
609

Agnitum Outpost
Trojan.PWS.Banbra
7.1.1

avast!
Win32:Malware-gen
2014.9-150606

AVG
Downloader.Generic14
2016.0.3087

Baidu Antivirus
Trojan.Win32.Banker
4.0.3.1566

Bitdefender
Gen:Variant.Symmi.45916
1.0.20.785

Emsisoft Anti-Malware
Gen:Variant.Symmi.45916
8.15.06.06.05

ESET NOD32
Win32/TrojanDownloader.Delf.BGN
9.11644

Fortinet FortiGate
W32/Banbra.BGN!tr
6/6/2015

F-Secure
Gen:Variant.Symmi.45916
11.2015-06-06_7

G Data
Gen:Variant.Symmi.45916
15.6.25

IKARUS anti.virus
AdWare.Win32.Wingo
t3scan.1.8.9.0

K7 AntiVirus
Trojan-Downloader
13.204.15946

Kaspersky
Trojan-Banker.Win32.Banbra
14.0.0.1929

Malwarebytes
Trojan.Downloader
v2015.06.06.05

McAfee
RDN/PWS-Banker!dx
5600.6743

MicroWorld eScan
Gen:Variant.Symmi.45916
16.0.0.471

NANO AntiVirus
Trojan.Win32.Urelas.bdmnfz
0.30.24.1357

Panda Antivirus
Generic Suspicious
15.06.06.05

Qihoo 360 Security
HEUR/QVM17.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_BANLOAD.YWNIB
7.2.157

Trend Micro
TROJ_BANLOAD.YWNIB
10.465.06

VIPRE Antivirus
Trojan.Win32.Generic
40340

File size:
442 KB (452,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\flashplayer16.exe

File PE Metadata
Compilation timestamp:
5/12/2015 12:37:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:qW6JywQ/F/7yOIJTJE9+8tcCuPJQ+atgoNbWXTJvxnJAXcx8m87Gx9T:qW6u/hyOIJFs+fC1BgtXFvpJAXcx8C

Entry address:
0x1000

Entry point:
B8, E8, B0, 5B, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 13, 5F, AC, 93, F6, DA, 0E, 49, B8, 88, 70, B9, 7F, 02, E4, D4, E7, A3, 09, EC, C0, 98, A1, 5C, B1, A8, F6, E3, C3, 31, 09, CF, 1F, C1, 4E, AB, B4, 5C, ED, 5C, 9F, 7F, 67, 31, 46, 42, 2A, F2, AE, C0, 51, E7, 04, 3B, B8, 82, D5, 97, 37, 7C, 93, 78, 0D, 1B, 57, 90, E9, A5, 95, D9, 44, 96, 60, DD, 40, F4, C1, F9, 67, 8C, 66, A6, EB, 35, FD, 1D, 17, 29, D6, 74, 16, EA, 22...
 
[+]

Packer / compiler:
PECompact v2

Code size:
838 KB (858,112 bytes)

The file flashplayer16.exe has been seen being distributed by the following 2 URLs.

Remove flashplayer16.exe - Powered by Reason Core Security