updateflashplayer_59519c27.exe

test

The executable updateflashplayer_59519c27.exe has been detected as malware by 36 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Product:
test

Description:
test Microsoft

Version:
1, 0, 0, 1

MD5:
df5ab239bdf09a8716cabbdfa1d6a724

SHA-1:
9dc24eba23867b252d32bd0564069a433d745323

SHA-256:
d17a22cd710e0420edc262472684fcbe8c9db6212fcb6b082d1e56eb927d43f6

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/1/2025 8:44:26 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.APV
-40

AegisLab AV Signature
Troj.W32.Generic!c
2.1.4+

AhnLab V3 Security
Spyware/Win32.Zbot.R96469
3.8.3.16

Avira AntiVirus
TR/Drop.Rovnix.11
8.3.3.4

Arcabit
Trojan.Inject.APV
1.0.0.798

avast!
Win32:Crypt-QNU [Trj]
2014.9-170315

AVG
PSW.Generic12
2018.0.2438

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17315

Bitdefender
Trojan.Inject.APV
1.0.20.370

Bkav FE
W32.GenericTesughM.Trojan
1.3.0.8876

Comodo Security
UnclassifiedMalware
26745

Dr.Web
Trojan.Packed.25602
9.0.1.074

Emsisoft Anti-Malware
Trojan.Inject.APV
8.17.03.15.04

ESET NOD32
Win32/Injector.AWQU (variant)
11.15076

Fortinet FortiGate
W32/ZBOT.QU!tr
3/15/2017

F-Secure
Trojan.Inject.APV
11.2017-15-03_4

G Data
Trojan.Inject.APV
17.3.A:25.11150B:25.9068

IKARUS anti.virus
Trojan-Downloader.Win32.Upatre
0.2.1.2

K7 AntiVirus
Trojan
13.10.4.22688

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1313

Malwarebytes
Trojan.Injector.ED
v2017.03.15.04

McAfee
Dowloader-FEX
5600.6094

Microsoft Security Essentials
VirTool:Win32/CeeInject
1.1.13504.0

MicroWorld eScan
Trojan.Inject.APV
18.0.0.222

NANO AntiVirus
Trojan.Win32.Zbot.ctitdq
1.0.70.15657

Panda Antivirus
Trj/CI.A
17.03.15.04

Qihoo 360 Security
Win32/Trojan.a52
1.0.0.1120

Quick Heal
TrojanPWS.Zbot.A4
3.17.14.00

Rising Antivirus
Trojan.Generic (cloud:lduLGXo5ayM)
23.00.65.17313

Sophos
Mal/Zbot-OA
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
8534

Trend Micro House Call
TROJ_SPNR.0BB514
7.2.74

Trend Micro
TROJ_SPNR.0BB514
10.465.15

VIPRE Antivirus
Trojan.Win32.Fareit.if
56600

ViRobot
Trojan.Win32.Z.Zbot.145721.B[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Zbot.Win32.147241
2.0.0.3230

File size:
142.3 KB (145,721 bytes)

Product version:
1, 0, 0, 1

Copyright:
(C) 2009

Original file name:
test.EXE

File type:
Executable application (Win32 EXE)

Language:
Greek (Greece)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_59519c27.exe

File PE Metadata
Compilation timestamp:
1/29/2014 9:13:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x187E

Entry point:
55, 8B, EC, 6A, FF, 68, 30, 26, 40, 00, 68, 92, 1A, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, C8, 21, 40, 00, 59, 83, 0D, B4, 33, 40, 00, FF, 83, 0D, B8, 33, 40, 00, FF, FF, 15, C4, 21, 40, 00, 8B, 0D, A8, 33, 40, 00, 89, 08, FF, 15, C0, 21, 40, 00, 8B, 0D, A4, 33, 40, 00, 89, 08, A1, BC, 21, 40, 00, 8B, 00, A3, B0, 33, 40, 00, E8, A2, 01, 00, 00, 39, 1D, C0, 30, 40, 00, 75, 0C, 68, 8E, 1A, 40, 00, FF, 15...
 
[+]

Entropy:
7.6294

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
4 KB (4,096 bytes)

Remove updateflashplayer_59519c27.exe - Powered by Reason Core Security