updateflashplayer_d4f92b18.exe

The executable updateflashplayer_d4f92b18.exe has been detected as malware by 34 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
d702213c5a26ed159361bdc88874b806

SHA-1:
4a26c09ea6a8e52601c8d29897a829db28bd920c

SHA-256:
0442e44cd69a93ed630a0f48f5ac26a4bdc1a4a7bb3f50bee903c972aabe3ea7

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/1/2025 8:44:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.81475
-40

Agnitum Outpost
Trojan.Cidox
7.1.1

AhnLab V3 Security
Trojan/Win32.Zbot
2015.03.07

Avira AntiVirus
TR/Dropper.Gen
7.11.214.140

avast!
Win32:Inject-BEK [Trj]
2014.9-170315

AVG
Generic35
2018.0.2438

Baidu Antivirus
Trojan.Win32.Rovnix
4.0.3.17315

Bitdefender
Gen:Variant.Zusy.81475
1.0.20.370

Comodo Security
TrojWare.Win32.Injector.AWZN
21319

Dr.Web
Trojan.DownLoader9.22851
9.0.1.074

Emsisoft Anti-Malware
Gen:Variant.Zusy.81475
8.17.03.15.04

ESET NOD32
Win32/Rovnix
11.11282

Fortinet FortiGate
W32/Zbot.OA!tr
3/15/2017

F-Secure
Gen:Variant.Zusy.81475
11.2017-15-03_4

G Data
Gen:Variant.Zusy.81475
17.3.25

IKARUS anti.virus
Virus.Win32.CeeInject
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.200.15187

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1313

Malwarebytes
Trojan.Agent.ED
v2017.03.15.04

McAfee
PWSZbot-FMU!D702213C5A26
5600.6094

Microsoft Security Essentials
VirTool:Win32/CeeInject.gen!KK
1.1.11400.0

MicroWorld eScan
Gen:Variant.Zusy.81475
18.0.0.222

NANO AntiVirus
Trojan.Win32.Fraud.csvspy
0.30.0.296

Norman
Troj_Generic.SJVUG
11.20170315

Panda Antivirus
Trj/CI.A
17.03.15.04

Qihoo 360 Security
Win32/Trojan.803
1.0.0.1015

Quick Heal
TrojanPWS.Zbot.Gen
3.17.14.00

Sophos
Mal/Zbot-OA
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Loktrom
8534

Trend Micro House Call
TROJ_SPNR.0BB414
7.2.74

Trend Micro
TROJ_SPNR.0BB414
10.465.15

Vba32 AntiVirus
Trojan.Inject
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Fareit.if
38188

Zillya! Antivirus
Trojan.Cidox.Win32.5980
2.0.0.2090

File size:
164 KB (167,936 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_d4f92b18.exe

File PE Metadata
Compilation timestamp:
1/17/2014 12:23:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x5D7E

Entry point:
55, 8B, EC, 6A, FF, 68, 90, 78, 40, 00, 68, 66, 5F, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 54, 72, 40, 00, 59, 83, 0D, E4, 9A, 40, 00, FF, 83, 0D, E8, 9A, 40, 00, FF, FF, 15, 58, 72, 40, 00, 8B, 0D, D8, 9A, 40, 00, 89, 08, FF, 15, 5C, 72, 40, 00, 8B, 0D, D4, 9A, 40, 00, 89, 08, A1, 60, 72, 40, 00, 8B, 00, A3, E0, 9A, 40, 00, E8, 78, 01, 00, 00, 39, 1D, 60, 90, 40, 00, 75, 0C, 68, 62, 5F, 40, 00, FF, 15, 64, 72...
 
[+]

Entropy:
7.4887

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
88 KB (90,112 bytes)

Remove updateflashplayer_d4f92b18.exe - Powered by Reason Core Security