fp_setup_winax.exe

Adobe Flash Player

Bit-Trejd

The executable fp_setup_winax.exe has been detected as malware by 8 anti-virus scanners.
Publisher:
Bit-Trejd LLC  (signed by Bit-Trejd)

Product:
Adobe Flash Player

Version:
21.0.0.213

MD5:
93ccbbebaf02eb17d01adb0c77b9f82d

SHA-1:
6a963bc79c6b2087df236b62ccf15f57cf89e487

SHA-256:
12d112dd406535e561904e69bb7e25aab3569bfb55de6f28e20d1080c1cc72b9

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
11/15/2024 9:46:16 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Karamanak!c
2.1.4+

AhnLab V3 Security
Malware/Win32.Generic.N2021061585
3.7.5.15

Dr.Web
Trojan.MulDrop6.44482
9.0.1.0249

Fortinet FortiGate
W32/Karamanak.AE!tr
9/5/2016

Kaspersky
Trojan.Win32.Karamanak
14.0.0.-359

McAfee
Artemis!93CCBBEBAF02
5600.6285

Panda Antivirus
Trj/CI.A
16.09.05.06

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
149.2 KB (152,800 bytes)

Product version:
21.0.0.213

Copyright:
Copyright (©) 1996-2016 Bit-Trejd LLC

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fp_setup_winax.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/30/2016 3:00:00 AM

Valid to:
5/31/2017 2:59:59 AM

Subject:
CN=Bit-Trejd, OU=IT, O=Bit-Trejd, STREET=1st Kolobovskij pereulok d. 27/3 str.3 office 30, L=Moscow, S=Moscow, PostalCode=127051, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
54460E1FCD612CD3377AC2CD76E4240F

File PE Metadata
Compilation timestamp:
6/10/2016 9:41:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
3072:qJPRs/EUpDRwDpiE5CRlluymcBla3Vb52/uJ8Vl:yoEUpDRIP6rZmtu

Entry address:
0x69E1

Entry point:
E8, 39, 5C, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, E0, E3, 41, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, E4, E3, 41, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 9B, 48, 00, 00, 85, C0, 75, 06, B8, 48, E5, 41, 00, C3, 83, C0, 08, C3, E8, 88, 48, 00, 00, 85, C0, 75, 06, B8, 4C, E5, 41, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
91.5 KB (93,696 bytes)

Remove fp_setup_winax.exe - Powered by Reason Core Security