flashupdate_20.3.3.exe

The executable flashupdate_20.3.3.exe has been detected as malware by 27 anti-virus scanners. The file has been seen being downloaded from storage-eu-3.sharefile.com.
MD5:
e9059dec529a70280a8f12697f9b4029

SHA-1:
625ed7a0b51555e5c86b6a08de479aef0adc7ca2

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
11/27/2024 11:25:09 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Luhe.Fiha.Gen!c
2.1.4+

Agnitum Outpost
Trojan.DR.Dapato
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.241763
8.3.2.4

Arcabit
Trojan.Generic.DED8AA5
1.0.0.646

avast!
Win32:Malware-gen
2014.9-160324

AVG
Luhe.Fiha.A
2017.0.2794

Bitdefender
Trojan.Generic.15567525
1.0.20.420

Comodo Security
UnclassifiedMalware
24001

Dr.Web
Trojan.DownLoader18.42151
9.0.1.084

Emsisoft Anti-Malware
Trojan.Generic.15567525
8.16.03.24.10

ESET NOD32
MSIL/Kryptik.ETG (variant)
10.12909

Fortinet FortiGate
MSIL/Injector.NLD!tr
3/24/2016

F-Secure
Trojan.Generic.15567525
11.2016-24-03_5

G Data
Trojan.Generic.15567525
16.3.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.9.5.0

Kaspersky
Trojan-Dropper.Win32.Dapato
14.0.0.465

Malwarebytes
Backdoor.Agent.SRV
v2016.03.24.10

McAfee
RDN/Generic PWS.y
5600.6450

Microsoft Security Essentials
TrojanSpy:MSIL/Omaneat.B
1.1.12400.0

MicroWorld eScan
Trojan.Generic.15567525
17.0.0.252

NANO AntiVirus
Trojan.Win32.DownLoader18.dzqivh
1.0.14.5380

nProtect
Trojan.Generic.15567525
16.01.22.01

Panda Antivirus
Trj/CI.A
16.03.24.10

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00XC0DA916
10.465.24

VIPRE Antivirus
Trojan.Win32.Generic
46688

File size:
580.5 KB (594,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\flashupdate_20.3.3.exe

File PE Metadata
Compilation timestamp:
1/4/2016 7:10:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:KQGrvSRyTqRPI8FQQ1+3C5Wun+XnnWhskzJ9TvCEiReh7ugk/JxIWxJNBSdL5lFX:KbSgmRPI871JmWGFw7ugwXslFP

Entry address:
0x5B46E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2739

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
357.5 KB (366,080 bytes)

The file flashupdate_20.3.3.exe has been seen being distributed by the following URL.

Remove flashupdate_20.3.3.exe - Powered by Reason Core Security