adobe flash player 14_10_2015.exe

Softwares 009BR

The executable adobe flash player 14_10_2015.exe has been detected as malware by 18 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
Publisher:
Softwares 009BR

Description:
Softwares 009BR

Version:
239.238.237.1258

MD5:
805b7da4d5faf4c5e70e31479a847c22

SHA-1:
2ae9aa888efe9af59f2364636acf5c7145450389

SHA-256:
2eea46836bf4549bb1daf3ec18b71feb3ad576908db910202167917542cc878b

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/25/2024 7:13:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.249117
476

Agnitum Outpost
Trojan.DL.Banload
7.1.1

Avira AntiVirus
TR/Dldr.Agent.1315328.2
8.3.2.2

AVG
Generic36
2016.0.2954

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.151016

Bitdefender
Gen:Variant.Graftor.249117
1.0.20.1445

Emsisoft Anti-Malware
Gen:Variant.Graftor.249117
8.15.10.16.09

ESET NOD32
Win32/TrojanDownloader.Banload.WPK (variant)
9.12419

Fortinet FortiGate
W32/Banload.WPK!tr.dldr
10/16/2015

F-Secure
Gen:Variant.Graftor.249117
11.2015-16-10_6

G Data
Gen:Variant.Graftor.249117
15.10.25

IKARUS anti.virus
Trojan-Downloader.Win32.Banload
t3scan.1.9.5.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1265

McAfee
GenericR-ESK!805B7DA4D5FA
5600.6610

Microsoft Security Essentials
TrojanDownloader:Win32/Banload
1.1.12101.0

MicroWorld eScan
Gen:Variant.Graftor.249117
16.0.0.867

Reason Heuristics
Threat.Win.Reputation.IMP
15.11.9.11

VIPRE Antivirus
Trojan.Win32.Generic
44582

File size:
1.3 MB (1,315,328 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Sueco (Suécia)

Common path:
C:\users\{user}\downloads\adobe flash player 14_10_2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:V3kf0PxW5AcELSY4DvUZQ92cpVhCwEEomsfsGu7hALC3TU+guhf8:VIvjYMvUZQEAYlMgOTPgut

Entry address:
0xFD650

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, D1, 18, 00, E8, F4, 93, F0, FF, 68, E8, D6, 18, 00, 6A, 00, 6A, 00, E8, C6, 96, F0, FF, E8, 41, 98, F0, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, 78, 74, 19, 00, 8B, 00, E8, 46, FD, F6, FF, A1, 78, 74, 19, 00, 8B, 00, E8, B6, FB, F6, FF, 6A, EC, A1, 78, 74, 19, 00, 8B, 00, 8B, 40, 30, 50, E8, F8, 9F, F0, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, A1, 78, 74, 19, 00, 8B, 00, 8B, 40, 30, 50, E8, 00, A2, F0, FF, 8B, 0D, 7C, 74, 19, 00, A1, 78, 74, 19, 00, 8B, 00, 8B, 15, B0, B3, 18, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1010 KB (1,034,240 bytes)

The file adobe flash player 14_10_2015.exe has been seen being distributed by the following URL.

Remove adobe flash player 14_10_2015.exe - Powered by Reason Core Security