adobe flash player-2015.exe

The application adobe flash player-2015.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from storage.googleapis.com.
MD5:
c70a657922bb9359f63efef43c75175d

SHA-1:
005dbde512a5168a4d590f9201762e579a871ad4

SHA-256:
fdd9734d90ba7465eedaa536f72a565866be9611b5fc7c3291ed03f73736ae33

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 12:35:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2802621
447

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Dldr.Agent.1158144.3
8.3.2.2

Arcabit
Trojan.Generic.D2AC3BD
1.0.0.590

avast!
Win32:Banker-MLE [Trj]
2014.9-151114

AVG
Downloader.Banload2
2016.0.2925

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.151114

Bitdefender
Trojan.GenericKD.2802621
1.0.20.1590

Emsisoft Anti-Malware
Trojan.GenericKD.2802621
8.15.11.14.07

ESET NOD32
Win32/TrojanDownloader.Banload.WPN trojan
6.3.12010.0

Fortinet FortiGate
W32/Banload.WPN!tr.dldr
11/14/2015

F-Prot
W32/Banload.AWZ
4.6.5.141

F-Secure
Trojan.GenericKD.2802621
11.2015-14-11_7

G Data
Trojan.GenericKD.2802621
15.11.25

IKARUS anti.virus
Trojan-Downloader.Win32.Banload
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.212.17767

Kaspersky
Trojan-Downloader.Win32.Delf
14.0.0.1121

McAfee
Artemis!C70A657922BB
5600.6581

Microsoft Security Essentials
TrojanDownloader:Win32/Banload.BFB
1.1.12205.0

MicroWorld eScan
Trojan.GenericKD.2802621
16.0.0.954

NANO AntiVirus
Trojan.Win32.Delf.dycfis
0.30.26.4437

nProtect
Trojan.GenericKD.2802621
15.11.06.01

Panda Antivirus
Trj/Genetic.gen
15.11.14.07

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R047C0DJN15
10.465.14

VIPRE Antivirus
Trojan.Win32.Generic
45042

Zillya! Antivirus
Adware.PullUpdate.Win32.79668
2.0.0.2496

File size:
1.1 MB (1,158,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe flash player-2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:eZMnwHXFxIW5Au2cTuoAdUFq3fYHPzzWGlM/JPzI2FjWTU+P:eZSnciHeFq3HKjTPP

Entry address:
0xF3B1C

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, FC, 36, 4F, 00, E8, C3, 2D, F1, FF, 8B, 1D, 8C, C6, 4F, 00, 8B, 03, E8, 4A, B6, F8, FF, 8B, 03, BA, C0, 3B, 4F, 00, E8, 36, B2, F8, FF, 8B, 0D, 44, C8, 4F, 00, 8B, 03, 8B, 15, A4, 40, 4C, 00, E8, 43, B6, F8, FF, 8B, 0D, 88, C8, 4F, 00, 8B, 03, 8B, 15, 18, 21, 4E, 00, E8, 30, B6, F8, FF, 8B, 0D, 2C, C6, 4F, 00, 8B, 03, 8B, 15, A0, 1D, 4F, 00, E8, 1D, B6, F8, FF, 8B, 0D, 6C, C4, 4F, 00, 8B, 03, 8B, 15, 98, 31, 4F, 00, E8, 0A, B6, F8, FF, 8B, 0D, 70, C7, 4F, 00, 8B, 03, 8B, 15...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
971 KB (994,304 bytes)

The file adobe flash player-2015.exe has been seen being distributed by the following URL.

Remove adobe flash player-2015.exe - Powered by Reason Core Security