instaall_flashhplayers86x64_msssd_aa_aih.exe

resex

The executable instaall_flashhplayers86x64_msssd_aa_aih.exe has been detected as malware by 20 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from feidowns.com.
Product:
resex

Version:
1.0.0.0

MD5:
2a4694c343e4873ac83e26099fe2174b

SHA-1:
ded80ae8fca5894e1735b20be892102b3828fd01

SHA-256:
d3aec31012014a05aa821a06d514615c378da2ed6f031b7b5f3ace7893d8fa67

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
11/27/2024 8:43:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.541895
714

Avira AntiVirus
TR/Downloader.A.10935
7.11.205.208

avast!
Win32:Malware-gen
2014.9-150221

AVG
Downloader.Generic14
2016.0.3192

Baidu Antivirus
Trojan.MSIL.Downloader
4.0.3.15221

Bitdefender
Gen:Variant.Kazy.541895
1.0.20.260

Dr.Web
Trojan.DownLoader12.11592
9.0.1.052

Emsisoft Anti-Malware
Gen:Variant.Kazy.541895
8.15.02.21.04

ESET NOD32
MSIL/TrojanDropper.Agent.BKZ
9.11090

Fortinet FortiGate
W32/Agent.HKM!tr.dldr
2/21/2015

F-Secure
Gen:Variant.Kazy.541895
11.2015-21-02_7

G Data
Gen:Variant.Kazy.541895
15.2.25

Kaspersky
Trojan-Downloader.MSIL.Agent
14.0.0.2454

McAfee
Artemis!2A4694C343E4
5600.6848

MicroWorld eScan
Gen:Variant.Kazy.541895
16.0.0.156

NANO AntiVirus
Trojan.Win32.Agent.dmwdug
0.30.0.65070

Panda Antivirus
Generic Suspicious
15.02.21.04

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
37064

File size:
637.5 KB (652,800 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
resex.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\instaall_flashhplayers86x64_msssd_aa_aih.exe

File PE Metadata
Compilation timestamp:
1/23/2015 4:29:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Ucm8q72xUXce4frmAkxduicBKI+FQl/epc41h5uGXEXSecEiP/3IWVE/uxPciMYs:tm8q72xUXnu9+FQl/ZSnXu/cs

Entry address:
0x9802E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2146

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
600.5 KB (614,912 bytes)

The file instaall_flashhplayers86x64_msssd_aa_aih.exe has been seen being distributed by the following URL.

Remove instaall_flashhplayers86x64_msssd_aa_aih.exe - Powered by Reason Core Security