flashplayer24.exe

The executable flashplayer24.exe has been detected as malware by 2 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage-eu-5.sharefile.com.
Version:
16.11.1.10

MD5:
9f464c7081dfe812be03eff89f045879

SHA-1:
d4d3e7547944e87a9c508f984a29e55344512eae

SHA-256:
9ace99e8a6d10cfebaada1304d87788243e376ce1c10b0695aa82a5b236f4a1a

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
11/27/2024 9:40:34 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/TrojanDownloader.Delf.BNZ trojan
7.0.302.0

Norman
Gen:Variant.Zusy.179612
03.02.2016 10:30:35

File size:
489.5 KB (501,248 bytes)

Product version:
16.11.1.10

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\{random}\flashplayer24.exe

File PE Metadata
Compilation timestamp:
2/2/2016 1:49:34 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:JmX2Qcg88A3RePeOERfcdrcCj9QK+5dcJNB:Ccg3A0eJfcdrcCBQ9d

Entry address:
0x1000

Entry point:
B8, 94, 80, 54, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 2F, 9C, FE, A2, CA, 40, E3, 38, 9A, 74, 9C, 05, C3, DC, B8, 91, 9F, 40, 45, C2, 52, 40, 46, 8D, 9F, 18, 30, 13, 0C, 1A, C8, 98, 60, 89, AC, D9, 74, 74, A6, 46, 27, 70, EC, 0D, E3, D7, 78, 16, 8E, 87, 99, C2, F1, 34, A5, 55, F7, F1, EA, AC, C5, C2, 30, B6, B5, CC, AD, AA, 8E, 2B, D9, 59, 9B, 82, E6, EA, 7A, F7, 8A, 18, 0C, 5A, FB, 63, C9, 72, B4, CC, 1B, CE, A7, E3, 8E...
 
[+]

Packer / compiler:
PECompact v2

Code size:
829 KB (848,896 bytes)

The file flashplayer24.exe has been seen being distributed by the following URL.

Remove flashplayer24.exe - Powered by Reason Core Security