flashplayersetup__3873_i260980696_il3.exe

The executable flashplayersetup__3873_i260980696_il3.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from cldlr.com.
MD5:
465e91ad09f6bfe770993021193e62f1

SHA-1:
3f26361a7fd7903563893e952a9ad9ae676d0c0d

SHA-256:
cf226a03ce26e10f06318875f8a467edcc1a271b542200f083e53cdd5bc55267

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/30/2024 9:06:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
(M)
16.6.7.0

File size:
329.5 KB (337,448 bytes)

File type:
Executable application (Win16 EXE)

Common path:
C:\users\{user}\downloads\flashplayersetup__3873_i260980696_il3.exe

File PE Metadata
Compilation timestamp:
1/13/2014 5:56:52 PM

OS version:
5.1

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:kdDbAmODbcf6DdkTzstB8r/Zy7dFve8jMy9Nna5NJtUbSb/0yKVTz3B8p5:kdXAm8bBdkToX8r/ad9wHJtUWKVTSp5

Entry address:
0x26BC3

Entry point:
E8, 74, 96, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Code size:
229 KB (234,496 bytes)

The file flashplayersetup__3873_i260980696_il3.exe has been seen being distributed by the following URL.

Remove flashplayersetup__3873_i260980696_il3.exe - Powered by Reason Core Security