flashplayer_update.exe

Product

The executable flashplayer_update.exe has been detected as malware by 22 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.txtpadonline.com.
Product:
Product

Version:
1.0.0.0

MD5:
e85aba22613fccc358480c15b94513a8

SHA-1:
1bd662a4bb4d2f7be22fb223e32412721adfa6d5

SHA-256:
a5bf60c78d6eb1c00306a394ac589b04e59bfb3c1ee0b421e7aaa80ff2a92c0d

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
12/28/2024 4:57:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.BNME
347

AhnLab V3 Security
Trojan/Win32.Banload
2015.10.17

Avira AntiVirus
TR/Dropper.MSIL.210897
8.3.2.2

Arcabit
Trojan.Agent.BNME
1.0.0.582

avast!
Win32:Malware-gen
2014.9-160223

AVG
Downloader.MSIL
2017.0.2825

Baidu Antivirus
Trojan.MSIL.Banload
4.0.3.16223

Bitdefender
Trojan.Agent.BNME
1.0.20.270

Emsisoft Anti-Malware
Trojan.Agent.BNME
8.16.02.23.09

ESET NOD32
MSIL/TrojanDownloader.Banload.EZ (variant)
10.12421

Fortinet FortiGate
MSIL/Banload.EV!tr.dldr
2/23/2016

F-Secure
Trojan.Agent.BNME
11.2016-23-02_3

G Data
Trojan.Agent.BNME
16.2.25

IKARUS anti.virus
Trojan-Downloader.MSIL.Banload
t3scan.1.9.5.0

McAfee
Artemis!E85ABA22613F
5600.6481

Microsoft Security Essentials
TrojanDownloader:MSIL/Banload.AB
1.1.12101.0

MicroWorld eScan
Trojan.Agent.BNME
17.0.0.162

nProtect
Trojan.Agent.BNME
15.10.16.01

Panda Antivirus
Trj/CI.A
16.02.23.09

Rising Antivirus
PE:Malware.RDM.39!5.2D[F1]
23.00.65.16221

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
44600

File size:
338 KB (346,112 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Template.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flashplayer_update.exe

File PE Metadata
Compilation timestamp:
10/14/2015 12:26:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:GzJ+lM+sEvWfROJLhfJpreQ00ws/R3b/rz3qhO1hS8p9CaOiZiV7xN:1WROJNhpeBUDnqbK9xK

Entry address:
0x2DE5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
176 KB (180,224 bytes)

The file flashplayer_update.exe has been seen being distributed by the following URL.

Remove flashplayer_update.exe - Powered by Reason Core Security