FlashToolLib.v1.dll threat report

MD5 5b4c4963185748795869a9e9a5a5194a
Latest seen 2022-05-15 23:35:49 (3 years ago)
First seen 2020-06-22 11:34:48 (5 years ago)
Size 2 MB
Publisher MediaTek Inc.

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for FlashToolLib.v1.dll. ThreatInfo currently classifies this sample as Trojan.Gen.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows FlashToolLib.v1.dll detected as Trojan.Gen. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
Trojan.Gen
Last analysis
2022-05-15 23:35:49 (3 years ago)
File hash
5b4c4963185748795869a9e9a5a5194a
Download Anti-Malware

FlashToolLib.v1.dll is a Windows file recorded in the ThreatInfo database. It is associated with BootROM and FlashTool Communication DLL.. The reported company name is MediaTek Inc.. The current detection status is Trojan.Gen, based on the latest analysis from 2022-05-15 23:35:49 (3 years ago).

If FlashToolLib.v1.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Gen.

Product Name: BootROM and FlashTool Communication DLL.
Company Name: MediaTek Inc.
MD5: 5b4c4963185748795869a9e9a5a5194a
Size: 2 MB
First Published: 2020-06-22 11:34:48 (5 years ago)
Latest Published: 2022-05-15 23:35:49 (3 years ago)
Status: Trojan.Gen (on last analysis)
Analysis Date: 2022-05-15 23:35:49 (3 years ago)
FlashToolLib.v1.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%desktop%\y5 2019 emui 9.1.0 from plusko www.teleed.ru\sp_flash_tool_v5.1824_win
%sysdrive%\$recycle.bin\s-1-5-21-1258497122-414944913-3601815398-1000\$rml2gbn.ru\sp_flash_tool_v5.1824_win
%sysdrive%\$recycle.bin\s-1-5-21-1258497122-414944913-3601815398-1000\$r78qksu.ru\sp_flash_tool_v5.1824_win
%sysdrive%\mobile tools and software\roms\y5 2019 frp bypass\y5 2019 emui 9.1.0 from plusko www.teleed.ru\sp_flash_tool_v5.1824_win
%profile%\downloads\herramientas a ocupar para quitar cuenta y5 2019 amn-lx3\2 y5 2019 emui 9.1.0\y5 2019 emui 9.1.0 servicell unlock\sp_flash_tool_v5.1824_win

ThreatInfo has observed FlashToolLib.v1.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

60.0%
20.0%
20.0%

The strongest geographic signal for this file is Ukraine with 60.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 7 80.0%
Windows 10 20.0%

The most common operating system signal for FlashToolLib.v1.dll is Windows 7 with 80.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

FlashToolLib.v1.dll is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x10000000
Entry Address: 0x003c7000

PE Sections:

Name Size of data MD5
.text 1931264 e271ad70671699d0207a9ee22e681cf3
.rdata 450048 89e42e5657fa0c283af99fe43e8770f7
.data 141824 ee4a23ba2dfbc6de74f5de027e3ea91d
.rsrc 2048 274b83d418494d773112158d19250744
.reloc 194560 e53233d38634eddbbd7ecd84f62b342b
.text 366080 f9bc07fa3b79253bea0b24beb7b004f7

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: