install_flashplayer.exe

The executable install_flashplayer.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from vv2.com.
MD5:
7caccca60cf8b9fca94de56f70f98241

SHA-1:
e050297bea8aeb2573461030909205ccffda9099

SHA-256:
ff198c75c4235c6fe838a9496c1184314b2d25fa4a5b881a788d5bf0f4965d57

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
1/9/2025 3:19:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Delf.238
793

Agnitum Outpost
Trojan.DR.Dorifel
7.1.1

Avira AntiVirus
DR/Delphi.Gen
7.11.138.30

avast!
Win32:Dropper-gen [Drp]
2014.9-141204

Baidu Antivirus
Trojan.Win32.Dorifel
4.0.3.14124

Bitdefender
Gen:Variant.Delf.238
1.0.20.1690

Comodo Security
UnclassifiedMalware
17965

Emsisoft Anti-Malware
Gen:Variant.Delf.238
8.14.12.04.09

Fortinet FortiGate
W32/Dorifel.AIPK!tr
12/4/2014

F-Secure
Gen:Variant.Delf.238
11.2014-04-12_5

G Data
Gen:Variant.Delf.238
14.12.24

K7 AntiVirus
Riskware
13.176.11510

Kaspersky
Trojan-Dropper.Win32.Dorifel
14.0.0.2848

Malwarebytes
Trojan.Agent.DF
v2014.12.04.09

McAfee
Artemis!7CACCCA60CF8
5600.6927

MicroWorld eScan
Gen:Variant.Delf.238
15.0.0.1014

NANO AntiVirus
Trojan.Script.Qhost.chhpdx
0.28.0.58491

Norman
Troj_Generic.SLRUG
11.20141204

Panda Antivirus
Generic Malware
14.12.04.09

Qihoo 360 Security
Win32/Trojan.166
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R021B01B214
7.2.338

VIPRE Antivirus
Trojan.Win32.Generic
27594

File size:
401 KB (410,624 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\install_flashplayer.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:HuY4dmGARY27mTK0V+0tKHID6C+q+bpPEyuFE9qiO2B2tujntgQ9RQiyCH3KV9sL:F4dm5RbaTlXXIp8/KqiLnKQ9oCH3Km7

Entry address:
0x5514C

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 5C, 4F, 45, 00, E8, 6B, 0A, FB, FF, 68, E0, 51, 45, 00, 6A, FF, 6A, 00, E8, 5D, 0C, FB, FF, 8B, D8, 85, DB, 74, 5D, E8, 22, 0D, FB, FF, 85, C0, 75, 54, A1, 88, 70, 45, 00, 8B, 00, E8, D2, DE, FF, FF, A1, 88, 70, 45, 00, 8B, 00, BA, 10, 52, 45, 00, E8, D1, DA, FF, FF, 8B, 0D, 68, 71, 45, 00, A1, 88, 70, 45, 00, 8B, 00, 8B, 15, 68, 46, 45, 00, E8, C1, DE, FF, FF, A1, 88, 70, 45, 00, 8B, 00, 8B, 40, 44, B2, 01, E8, 9C, 74, FF, FF, A1, 88, 70, 45, 00, 8B, 00, E8, 24, DF, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
337 KB (345,088 bytes)

The file install_flashplayer.exe has been seen being distributed by the following URL.

Remove install_flashplayer.exe - Powered by Reason Core Security