flash_player_installer.exe

WindowsFormsApplication1

The application flash_player_installer.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. The file has been seen being downloaded from amateurporntubed.com.
Product:
WindowsFormsApplication1

Version:
1.0.0.0

MD5:
90748f120313703aa0a1ee433dbc86fb

SHA-1:
4384014fb7073ff89d62715ac7014d957cf3d197

SHA-256:
b6652db028c39c1b467fcf917dc31d589e9d8797eb421c671163dbcbcc22bf3f

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
11/1/2024 12:25:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DR.Chextad
7.1.1

Avira AntiVirus
TR/Agent.18432.146
7.11.213.24

avast!
Win32:Trojan-gen
2014.9-160516

AVG
Dropper.Small
2017.0.2742

Baidu Antivirus
Trojan.MSIL.Chextad
4.0.3.16516

Comodo Security
UnclassifiedMalware
21263

Dr.Web
Adware.Plugin.17
9.0.1.0137

Fortinet FortiGate
W32/Chextad.B!tr
5/16/2016

IKARUS anti.virus
Trojan-Dropper.MSIL
t3scan.1.8.6.0

Kaspersky
Trojan-Dropper.MSIL.Chextad
14.0.0.203

McAfee
Artemis!90748F120313
5600.6398

Microsoft Security Essentials
Trojan:Win32/Meredrop
1.1.11400.0

NANO AntiVirus
Trojan.Win32.Chextad.diebqn
0.30.0.296

Norman
Suspicious_Gen4.BEJCB
11.20160516

Panda Antivirus
Trj/OCJ.A
16.05.16.08

Qihoo 360 Security
Win32/Trojan.Dropper.1f4
1.0.0.1015

VIPRE Antivirus
Trojan.Win32.Generic
38040

Zillya! Antivirus
Dropper.Chextad.Win32.1
2.0.0.2085

File size:
18 KB (18,432 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
WindowsFormsApplication1.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flash_player_installer.exe

File PE Metadata
Compilation timestamp:
9/21/2012 2:18:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:YmrLqdLuLkL+LuiCLnLnvsS3sNuSW6b6P5fQ5anV0K4kCzYcHe+m:fOqolLnvsSccm+P50aV0K4RzYcHe+m

Entry address:
0x54AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.6664

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13.5 KB (13,824 bytes)

The file flash_player_installer.exe has been seen being distributed by the following URL.

Remove flash_player_installer.exe - Powered by Reason Core Security