What is FlashUtil32_32_0_0_207_Plugin.exe?

FlashUtil32_32_0_0_207_Plugin.exe is part of Adobe® Flash® Player Installer/Uninstaller and developed by Adobe according to the FlashUtil32_32_0_0_207_Plugin.exe version information.

FlashUtil32_32_0_0_207_Plugin.exe's description is "Adobe® Flash® Player Installer/Uninstaller 32.0 r0"

FlashUtil32_32_0_0_207_Plugin.exe is digitally signed by Adobe Inc..

FlashUtil32_32_0_0_207_Plugin.exe is usually located in the 'C:\Windows\SysWOW64\Macromed\Flash\' folder.

None of the anti-virus scanners at VirusTotal reports anything malicious about FlashUtil32_32_0_0_207_Plugin.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on FlashUtil32_32_0_0_207_Plugin.exe:

PropertyValue
Product nameAdobe® Flash® Player Installer/Uninstaller
Company nameAdobe
File descriptionAdobe® Flash® Player Installer/Uninstaller 32.0 r0
Internal nameAdobe® Flash® Player Installer/Uninstaller 32.0
Original filenameFlashUtil.exe
Legal copyrightCopyright © 1996-2019 Adobe
Legal trademarkAdobe® Flash® Player
Product version32,0,0,207
File version32,0,0,207

Here's a screenshot of the file properties when displayed by Windows Explorer:

Product nameAdobe® Flash® Player Installer/Uni..
Company nameAdobe
File descriptionAdobe® Flash® Player Installer/Uni..
Internal nameAdobe® Flash® Player Installer/Uni..
Original filenameFlashUtil.exe
Legal copyrightCopyright © 1996-2019 Adobe
Legal trademarkAdobe® Flash® Player
Product version32,0,0,207
File version32,0,0,207

Digital signatures [?]

FlashUtil32_32_0_0_207_Plugin.exe has a valid digital signature.

PropertyValue
Signer nameAdobe Inc.
Certificate issuer nameDigiCert EV Code Signing CA (SHA2)
Certificate serial number0d2caccd3e9eec06738410ba31bf6595

VirusTotal report

None of the 71 anti-virus programs at VirusTotal detected the FlashUtil32_32_0_0_207_Plugin.exe file.

None of the 71 anti-virus programs detected the FlashUtil32_32_0_0_207_Plugin.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_created": [
        "C:\\Windows\\System32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp"
    ],
    "directory_created": [
        "C:\\Windows\\System32\\Macromed\\Temp",
        "C:\\Windows\\System32\\Macromed",
        "C:\\Windows\\System32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\",
        "C:\\Windows\\System32\\Macromed\\Temp\\"
    ],
    "dll_loaded": [
        "C:\\Windows\\system32\\clbcatq.dll",
        "C:\\Windows\\system32\\riched20.dll",
        "kernel32",
        "C:\\Windows\\system32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp",
        "C:\\Windows\\system32\\Advapi32.dll",
        "api-ms-win-core-localization-l1-2-1",
        "C:\\Windows\\system32\\setupapi.dll",
        "kernel32.dll",
        "UxTheme.dll",
        "C:\\Windows\\system32\\ws2help.dll",
        "C:\\Windows\\system32\\ole32.dll",
        "C:\\Windows\\system32\\sfc_os.dll",
        "dwmapi.dll",
        "C:\\Windows\\system32\\xpsp2res.dll",
        "api-ms-win-core-synch-l1-2-0",
        "C:\\Windows\\system32\\uxtheme.dll",
        "C:\\Windows\\system32\\Msimg32.dll",
        "C:\\Windows\\system32\\secur32.dll",
        "C:\\Windows\\system32\\wintrust.dll",
        "C:\\Windows\\syswow64\\MSCTF.dll",
        "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
        "C:\\Windows\\system32\\msasn1.dll",
        "OLEAUT32.DLL",
        "C:\\Windows\\system32\\netapi32.dll",
        "C:\\Windows\\system32\\Shell32.dll",
        "C:\\Windows\\system32\\comres.dll",
        "C:\\Windows\\system32\\version.dll",
        "C:\\Windows\\system32\\kernel32.dll",
        "SHELL32.dll",
        "C:\\Windows\\system32\\cryptui.dll",
        "comctl32.dll",
        "C:\\Windows\\system32\\dinput8.dll",
        "C:\\Windows\\system32\\user32.dll",
        "C:\\Windows\\system32\\shdocvw.dll",
        "C:\\Windows\\system32\\psapi.dll",
        "api-ms-win-core-fibers-l1-1-1",
        "C:\\Windows\\system32\\ws2_32.dll",
        "C:\\Windows\\system32\\crypt32.dll",
        "C:\\Windows\\system32\\atl.dll"
    ],
    "file_opened": [
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Windows\\System32"
    ],
    "regkey_opened": [
        "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Mozilla Firefox 60.0.2\\extensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayerPepper",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
        "HKEY_LOCAL_MACHINE\\Software\\Mozilla",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Macromedia\\FlashPlayer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\RealNetworks\\RealPlayer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
        "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Firefox\\extensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Mozilla Firefox\\extensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.bin",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\msasn1",
        "HKEY_LOCAL_MACHINE\\Software\\MozillaPlugins\\@adobe.com\/FlashPlayer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
        "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayerPlugin",
        "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayerActiveX",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}"
    ],
    "file_written": [
        "C:\\Windows\\System32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp"
    ],
    "directory_removed": [
        "C:\\Windows\\SysWOW64\\Macromed\\Temp"
    ],
    "file_exists": [
        "C:\\Program Files (x86)\\Mozilla Firefox\\plugins\\NPSWF32.dll"
    ],
    "mutex": [
        "{FEC7EF28-53E7-4f06-8F56-FA6D670C8D3C}"
    ],
    "file_failed": [
        "C:\\Windows\\SysWOW64\\mms.cfg",
        "C:\\Windows\\SysWOW64\\Macromed\\Flash\\mms.cfg",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.dll"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
        "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Mozilla\\Mozilla Firefox 60.0.2\\extensions\\Plugins"
    ],
    "directory_enumerated": [
        "C:\\Windows\\SysWOW64\\Macromed\\Flash\\*",
        "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\*",
        "C:\\Windows\\SysWOW64\\Macromed\\Temp\\*",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\*.dll"
    ]
}

Dropped

[
    {
        "yara": [],
        "sha1": "fe7a7debdfec02ad9dbf2afb131f56e0347f1f05",
        "name": "35bd1ff76ef61bda_fpb.tmp",
        "filepath": "C:\\Windows\\SysWOW64\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp",
        "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
        "sha256": "35bd1ff76ef61bdacd8a0b519489105b291d2e8105bf5887c896947a0db50c27",
        "urls": [
            "http:\/\/crl4.digicert.com\/EVCodeSigningSHA2-g1.crl0K",
            "http:\/\/crl4.digicert.com\/sha2-assured-ts.crl0",
            "http:\/\/cacerts.digicert.com\/DigiCertSHA2AssuredIDTimestampingCA.crt0",
            "http:\/\/crl4.digicert.com\/DigiCertHighAssuranceEVRootCA.crl0",
            "http:\/\/cacerts.digicert.com\/DigiCertHighAssuranceEVRootCA.crt0",
            "http:\/\/ocsp.digicert.com0O",
            "http:\/\/crl3.digicert.com\/EVCodeSigningSHA2-g1.crl07",
            "http:\/\/crl3.digicert.com\/DigiCertAssuredIDRootCA.crl0P",
            "http:\/\/ocsp.digicert.com0I",
            "http:\/\/ocsp.digicert.com0H",
            "http:\/\/crl4.digicert.com\/DigiCertAssuredIDRootCA.crl0:",
            "http:\/\/cacerts.digicert.com\/DigiCertAssuredIDRootCA.crt0",
            "http:\/\/crl3.digicert.com\/DigiCertHighAssuranceEVRootCA.crl0",
            "http:\/\/crl3.digicert.com\/sha2-assured-ts.crl02",
            "http:\/\/cacerts.digicert.com\/DigiCertEVCodeSigningCA-SHA2.crt0",
            "https:\/\/www.digicert.com\/CPS0",
            "http:\/\/www.digicert.com\/ssl-cps-repository.htm0",
            "http:\/\/ocsp.digicert.com0C"
        ],
        "crc32": "BBB205F8",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/412\/files\/35bd1ff76ef61bda_fpb.tmp",
        "ssdeep": null,
        "size": 590904,
        "sha512": "3f0281d2e434f98d30ab47f50d25c625004b26eb8067092a1f21caf99ec9308f7a5594acaca307d88935995eba119d7d0b8d5859bb46464e8fa648a3f6e59a0d",
        "pids": [
            2800
        ],
        "md5": "b53c38b77f6832abc47d5759a07bdfe1"
    }
]

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.bin",
        "process_name": "3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.bin",
        "pid": 2800,
        "summary": {
            "file_created": [
                "C:\\Windows\\System32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp"
            ],
            "directory_created": [
                "C:\\Windows\\System32\\Macromed\\Temp",
                "C:\\Windows\\System32\\Macromed",
                "C:\\Windows\\System32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\",
                "C:\\Windows\\System32\\Macromed\\Temp\\"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\clbcatq.dll",
                "C:\\Windows\\system32\\riched20.dll",
                "kernel32",
                "C:\\Windows\\system32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp",
                "C:\\Windows\\system32\\Advapi32.dll",
                "api-ms-win-core-localization-l1-2-1",
                "C:\\Windows\\system32\\setupapi.dll",
                "kernel32.dll",
                "UxTheme.dll",
                "C:\\Windows\\system32\\ws2help.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "C:\\Windows\\system32\\sfc_os.dll",
                "dwmapi.dll",
                "C:\\Windows\\system32\\xpsp2res.dll",
                "api-ms-win-core-synch-l1-2-0",
                "C:\\Windows\\system32\\uxtheme.dll",
                "C:\\Windows\\system32\\Msimg32.dll",
                "C:\\Windows\\system32\\secur32.dll",
                "C:\\Windows\\system32\\wintrust.dll",
                "C:\\Windows\\syswow64\\MSCTF.dll",
                "API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
                "C:\\Windows\\system32\\msasn1.dll",
                "OLEAUT32.DLL",
                "C:\\Windows\\system32\\netapi32.dll",
                "C:\\Windows\\system32\\Shell32.dll",
                "C:\\Windows\\system32\\comres.dll",
                "C:\\Windows\\system32\\version.dll",
                "C:\\Windows\\system32\\kernel32.dll",
                "SHELL32.dll",
                "C:\\Windows\\system32\\cryptui.dll",
                "comctl32.dll",
                "C:\\Windows\\system32\\dinput8.dll",
                "C:\\Windows\\system32\\user32.dll",
                "C:\\Windows\\system32\\shdocvw.dll",
                "C:\\Windows\\system32\\psapi.dll",
                "api-ms-win-core-fibers-l1-1-1",
                "C:\\Windows\\system32\\ws2_32.dll",
                "C:\\Windows\\system32\\crypt32.dll",
                "C:\\Windows\\system32\\atl.dll"
            ],
            "file_opened": [
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Windows\\System32"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Mozilla Firefox 60.0.2\\extensions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayerPepper",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
                "HKEY_LOCAL_MACHINE\\Software\\Mozilla",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Macromedia\\FlashPlayer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\RealNetworks\\RealPlayer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
                "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Firefox\\extensions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Mozilla Firefox\\extensions",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.bin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\msasn1",
                "HKEY_LOCAL_MACHINE\\Software\\MozillaPlugins\\@adobe.com\/FlashPlayer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
                "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayerPlugin",
                "HKEY_LOCAL_MACHINE\\Software\\Macromedia\\FlashPlayerActiveX",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}"
            ],
            "file_written": [
                "C:\\Windows\\System32\\Macromed\\Temp\\{BAB78654-581A-4455-A6A4-D43633AAD235}\\fpb.tmp"
            ],
            "directory_removed": [
                "C:\\Windows\\SysWOW64\\Macromed\\Temp"
            ],
            "file_exists": [
                "C:\\Program Files (x86)\\Mozilla Firefox\\plugins\\NPSWF32.dll"
            ],
            "mutex": [
                "{FEC7EF28-53E7-4f06-8F56-FA6D670C8D3C}"
            ],
            "file_failed": [
                "C:\\Windows\\SysWOW64\\mms.cfg",
                "C:\\Windows\\SysWOW64\\Macromed\\Flash\\mms.cfg",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.dll"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
                "HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Mozilla\\Mozilla Firefox 60.0.2\\extensions\\Plugins"
            ],
            "directory_enumerated": [
                "C:\\Windows\\SysWOW64\\Macromed\\Flash\\*",
                "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\*",
                "C:\\Windows\\SysWOW64\\Macromed\\Temp\\*",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\*.dll"
            ]
        },
        "first_seen": 1560887586.8438,
        "ppid": 1512
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1560887586.5625,
        "ppid": 376
    }
]

Signatures

[
    {
        "markcount": 1,
        "families": [],
        "description": "Checks if process is being debugged by a debugger",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741700,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1560887587.7037,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 2127
            }
        ],
        "references": [],
        "name": "checks_debugger"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "E:\\r\\ws\\St_Make\\code\\build\\win\\int\\Morphology.build\\Release\\Win32\\Morpheme.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Tries to locate where the browsers are installed",
        "severity": 1,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Program Files (x86)\\Mozilla Firefox\\plugins\\NPSWF32.dll",
                "type": "ioc",
                "description": null
            },
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Mozilla\\Mozilla Firefox 60.0.2\\extensions\\Plugins",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "locates_browser"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".gfids",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "The file contains an unknown PE resource name possibly indicative of a packer",
        "severity": 1,
        "marks": [
            {
                "category": "resource name",
                "ioc": "LZMG",
                "type": "ioc",
                "description": null
            },
            {
                "category": "resource name",
                "ioc": "TYPELIB",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_unknown_resource_name"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Steals private information from local Internet browsers",
        "severity": 2,
        "marks": [
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Mozilla Firefox\\extensions",
                "type": "ioc",
                "description": null
            },
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\Software\\Mozilla\\Mozilla Firefox 60.0.2\\extensions",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "infostealer_browser"
    },
    {
        "markcount": 38,
        "families": [],
        "description": "Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32FirstW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "[System Process]",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 0
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 105
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "System",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 4
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 106
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "smss.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 252
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 107
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "csrss.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 328
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 108
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "wininit.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 376
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 109
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "csrss.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 384
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 110
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "winlogon.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 424
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 111
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "services.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 468
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 112
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "lsass.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 476
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 113
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "lsm.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 484
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 114
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 592
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 115
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 660
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 116
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 712
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 117
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 804
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 118
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 880
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 119
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 276
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 120
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 480
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 121
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "spoolsv.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1084
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 122
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1120
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 123
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1216
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 124
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1548
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 125
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "taskhost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1724
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 126
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "dwm.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1768
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 127
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "explorer.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1788
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 128
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "SearchIndexer.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1316
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 129
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "cmd.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1692
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 130
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "conhost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1700
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 131
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1000
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 132
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "wmpnetwk.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1856
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 133
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "python.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 2168
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 134
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "svchost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 3064
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 135
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "audiodg.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 2560
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 136
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "mobsync.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 552
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 137
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "python.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 2520
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 138
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "taskhost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 608
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 139
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "SearchProtocolHost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 1560
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 140
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "SearchFilterHost.exe",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 2456
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 141
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "Process32NextW",
                    "return_value": 1,
                    "arguments": {
                        "process_name": "3702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6.bin",
                        "snapshot_handle": "0x000000f0",
                        "process_identifier": 2800
                    },
                    "time": 1560887586.9848,
                    "tid": 2816,
                    "flags": {}
                },
                "pid": 2800,
                "type": "call",
                "cid": 142
            }
        ],
        "references": [],
        "name": "injection_process_search"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "The binary likely contains encrypted or compressed data indicative of a packer",
        "severity": 2,
        "marks": [
            {
                "entropy": 7.1903536065977,
                "section": {
                    "size_of_data": "0x00106800",
                    "virtual_address": "0x0005c000",
                    "entropy": 7.1903536065977,
                    "name": ".rsrc",
                    "virtual_size": "0x001066a4"
                },
                "type": "generic",
                "description": "A section with a high entropy has been found"
            },
            {
                "entropy": 0.7423117709438,
                "type": "generic",
                "description": "Overall entropy of this PE file is high"
            }
        ],
        "references": [
            "http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html",
            "http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf"
        ],
        "name": "packer_entropy"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.0798678398132,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5226,
            "time": 9.0796298980713,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7070,
            "time": 3.0120358467102,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7398,
            "time": 1.0257179737091,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7726,
            "time": 3.0194628238678,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8054,
            "time": 1.5379238128662,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8382,
            "time": -0.095813989639282,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 8710,
            "time": 1.5329020023346,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28120,
            "time": 1.0486299991608,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36504,
            "time": 3.1422328948975,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "4e33575d37442ec024110b20e9c70a1e11eb7b2951f24b83fb5e7960d6593a89",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "9952f945c0950bc1a2d154fb17583a95439e08ebab67f5536a15fad5ae02930d",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandbox

Folder name variants

FlashUtil32_32_0_0_207_Plugin.exe may also be located in other folders than C:\Windows\SysWOW64\Macromed\Flash\. The most common variants are listed below:

Hashes [?]

PropertyValue
MD52b3aa344117f9378077187ae5ab80380
SHA2563702e349168043181470a0e3e77ff978edfe37bcccd89b02712e39c21d67b5d6

Error Messages

These are some of the error messages that can appear related to flashutil32_32_0_0_207_plugin.exe:

flashutil32_32_0_0_207_plugin.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

flashutil32_32_0_0_207_plugin.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

Adobe® Flash® Player Installer/Uninstaller 32.0 r0 has stopped working.

End Program - flashutil32_32_0_0_207_plugin.exe. This program is not responding.

flashutil32_32_0_0_207_plugin.exe is not a valid Win32 application.

flashutil32_32_0_0_207_plugin.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


Free online surveys

And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply