FLVGuncelle.exe

AOE

The executable FLVGuncelle.exe has been detected as malware by 34 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.showmaskonnn.com.
Publisher:
AOE

Product:
AOE

Version:
305

MD5:
3e30967ca5ea4be8868e6fb652a540f5

SHA-1:
612b27ea99f57fc229482d92bee4b30f4526e728

SHA-256:
a5a0811620b59272d46b87bab57d118dd40fd88534c7047d6e46439d11cbb19a

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
2/26/2025 11:28:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.26338
936

Agnitum Outpost
Trojan.Blocker
7.1.1

AhnLab V3 Security
Trojan/Win32.Blocker
14.07.14

Avira AntiVirus
TR/Barys.26338.15
7.11.148.124

avast!
Win32:Ransom-ARZ [Trj]
2014.9-140714

AVG
Dropper.Generic9
2015.0.3414

Baidu Antivirus
Trojan.Win32.Ransomlock
4.0.3.14714

Bitdefender
Gen:Variant.Barys.26338
1.0.20.975

Comodo Security
UnclassifiedMalware
18240

Dr.Web
Trojan.Zipvideom.1
9.0.1.0195

Emsisoft Anti-Malware
Gen:Variant.Barys.26338
8.14.07.14.03

ESET NOD32
MSIL/Bepush (variant)
8.9775

Fortinet FortiGate
W32/Blocker.DOON!tr
7/14/2014

F-Secure
Trojan-Downloader:W32/Kilim.T
11.2014-14-07_2

G Data
Gen:Variant.Barys.26338
14.7.24

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.177.12026

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.3564

Malwarebytes
Trojan.Downloader.MSIL
v2014.07.14.03

McAfee
RDN/Ransom!ea
5600.7070

Microsoft Security Essentials
TrojanDropper:MSIL/Bepush.C
1.10502

MicroWorld eScan
Gen:Variant.Barys.26338
15.0.0.585

NANO AntiVirus
Trojan.Win32.Zipvideom.ctlvxo
0.28.0.59608

Norman
Suspicious_Gen5.ALHKO
11.20140714

Panda Antivirus
Generic Malware
14.07.14.03

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Quick Heal
TrojanDropper.Bepush.r3
7.14.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_FEBUSER.SE
7.2.195

Trend Micro
TROJ_FEBUSER.SE
10.465.14

Vba32 AntiVirus
Hoax.Blocker
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29006

XVirus List
Win32.Detected
2.7.14

Zillya! Antivirus
Trojan.Blocker.Win32.14469
2.0.0.1782

File size:
191 KB (195,584 bytes)

Product version:
305

Copyright:
AOE

Trademarks:
AOE

Original file name:
FLVGuncelle.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flvguncelle.exe

File PE Metadata
Compilation timestamp:
1/30/2014 10:36:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:6E3EIvZscHEeNUiZhYE/ibQx9yNgQlGGsww2BOHmKpSt6nojJjLA4FuwAu:6LIZkWHh9/ibe94lxrFQmKpSt6noZ

Entry address:
0x2FCEA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
183.5 KB (187,904 bytes)

The file FLVGuncelle.exe has been seen being distributed by the following URL.

Remove FLVGuncelle.exe - Powered by Reason Core Security