flux-setup.exe

The executable flux-setup.exe has been detected as malware by 16 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Infected by the Parite virus, a polymorphic file infecting virus that infects all portable EXE and SCR files found on local and shared network drives. The file has been seen being downloaded from justgetflux.com.
MD5:
19a7873837e4be63ea9e57ca0d982bd2

SHA-1:
49f57fbcde05a2d6d7733ed3cc580be8f9f81045

SHA-256:
ed5f05520471256920f5b4cbce29edde21c898b43e08e58366f833c652d3d751

Scanner detections:
16 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/23/2024 10:23:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Parite.B
5817690

Avira AntiVirus
W32/Parite
7.11.30.172

avast!
Parite
151217-3

AVG
Win32/Parite
2015.0.4489

Clam AntiVirus
Heuristics.W32.Parite.B
0.98/21181

Dr.Web
Win32.Parite.2
9.0.1.05190

Emsisoft Anti-Malware
Win32.Parite
10.0.0.5366

ESET NOD32
Win32/Parite.B virus
7.0.302.0

F-Prot
W32/Parite.B
4.6.5.141

F-Secure
Win32.Parite.B
5.15.21

Kaspersky
Virus.Win32.Parite
15.0.0.562

McAfee
Virus.W32/Pate.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.608.0

Norman
Win32.Parite.B
17.12.2015 06:34:11

Sophos
Virus 'W32/Parite-B'
5.22

VIPRE Antivirus
Threat.46249
45918

File size:
757 KB (775,130 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
12/6/2009 4:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:9X5NpKKrETxnxDWsMtGgvYGW621SMSTyte0eO9aVz2I8qCgrVgXwEAWgXm2L6T3W:9X5NdMxkfBYt6CSfetveOE2I8qCgrugX

Entry address:
0x39000

Entry point:
90, 90, 68, 04, 52, CD, 05, 58, 90, 90, BF, 20, 90, 43, 00, 68, 98, 05, 00, 00, 5E, FF, 34, 3E, 31, 04, 24, 8F, 04, 3E, 83, EE, 03, 4E, 75, F1, EC, 2F, CC, 05, 04, 52, CD, 05, 04, 52, 8D, 05, CF, 62, CD, 05, 3C, 4F, C4, 05, DE, 71, C4, 05, 04, E2, CF, 05, 05, 52, CD, 05, 64, 22, 8D, 05, 80, 2A, 8D, 05, 92, 2A, 8D, 05, BC, 30, CD, 05, 86, 2A, CD, 05, 90, 2A, CD, 05, 64, 0C, CD, 05, 86, 2A, CD, 05, 90, 2A, CD, 05, 04, 52, CD, 05, 04, 52, CD, 05, 04, 52, CD, 05, 04, 52, CD, 05, D0, 22, 8D, 05, 04, 52, CD, 05...
 
[+]

Entropy:
7.9612  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file flux-setup.exe has been seen being distributed by the following URL.

Remove flux-setup.exe - Powered by Reason Core Security