wintoflash.exe
This is a setup program which is used to install the application. The file has been seen being downloaded from gerenciador.baixaki.com.br and multiple other hosts.
MD5:
4c558ec6f2b9b53b8d0c7c494498bc9e
SHA-1:
1d1b3feab58c81d691301f7785d3778a4e16b905
SHA-256:
8efd5047d854c02326bd865c828b2ab77664cb10ab50d71403f9037a8c45f377
Scanner detections:
1 / 68
Status:
Clean (1 probable false positive detection)
Explanation:
This is mosty likely a false positive detection, the file is probably clean.
Analysis date:
4/16/2025 8:46:38 PM UTC (today)
Scan engine
Detection
Engine version
Vba32 AntiVirus
AdWare.Win64.Agent
3.12.26.3
File size:
32.5 MB (34,082,966 bytes)
File type:
Executable application (Win64 EXE)
Common path:
C:\users\{user}\downloads\wintoflash.exe
Compilation timestamp:
5/5/2059 1:41:57 AM
CTPH (ssdeep):
786432:1YC3qe231kpnzcj2qlGJk6eeoxSSf28jY6oKlPwaXpx5VjYXidn:lqVY/ob06TVX5x3YXih
The file wintoflash.exe has been seen being distributed by the following 2 URLs.
http://gerenciador.baixaki.com.br/nocache/programas/urls/iron/.../wintoflash-42-32-4102922.exe