adobe flash player 2015.exe

Flash Plugin Softwares

The executable adobe flash player 2015.exe, “Flash Plugin Softwares” has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from storage.googleapis.com.
Publisher:
Flash Plugin Softwares

Description:
Flash Plugin Softwares

Version:
32767.10568.10677.10565

MD5:
503c15fb9d3e8b18ad61def231f41303

SHA-1:
a7a7b13bbda8f8399005fc81025f209000a562fd

SHA-256:
c07dbb4b51c2985b601232842020f61d2ff477c0ce4025b368eb6d57d02e33f5

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
5/14/2024 4:10:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2611195
540

Agnitum Outpost
Trojan.DL.Banload
7.1.1

Avira AntiVirus
TR/Dldr.Banload.583
8.3.1.6

Arcabit
Trojan.Generic.D27D7FB
1.0.0.425

avast!
Win32:Banker-MDF [Trj]
2014.9-150813

AVG
Downloader.Banload2
2016.0.3018

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.15813

Bitdefender
Trojan.GenericKD.2611195
1.0.20.1125

Emsisoft Anti-Malware
Trojan.GenericKD.2611195
8.15.08.13.08

ESET NOD32
Win32/TrojanDownloader.Banload.WCL (variant)
9.12069

Fortinet FortiGate
W32/Banload.WCL!tr.dldr
8/13/2015

F-Secure
Trojan.GenericKD.2611195
11.2015-13-08_5

G Data
Trojan.GenericKD.2611195
15.8.25

IKARUS anti.virus
Virus.Win32.DelfInject
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.207.16832

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1586

McAfee
Artemis!503C15FB9D3E
5600.6674

Microsoft Security Essentials
TrojanDownloader:Win32/Pumba!rfn
1.1.11903.0

MicroWorld eScan
Trojan.GenericKD.2611195
16.0.0.675

nProtect
Trojan.GenericKD.2611195
15.08.07.01

Panda Antivirus
Trj/Genetic.gen
15.08.13.08

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R0C1C0DH615
10.465.13

VIPRE Antivirus
Trojan.Win32.Generic
42758

Zillya! Antivirus
Downloader.Banload.Win32.65992
2.0.0.2343

File size:
1.7 MB (1,788,928 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Uzbeque (Latino, Uzbequistão)

Common path:
C:\users\{user}\downloads\adobe flash player 2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Ya1MIJ/ntswNV7kezUZ8XzdQQRNwQtXn2TArTPP:Ya1MIJGwL28Xp9RBn

Entry address:
0x1746D8

Entry point:
55, 8B, EC, 83, C4, F0, B8, F8, 40, 57, 00, E8, F4, 22, E9, FF, 68, 70, 47, 57, 00, 6A, 00, 6A, 00, E8, 7A, 25, E9, FF, E8, 0D, 27, E9, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, 64, 14, 58, 00, 8B, 00, E8, 12, 5B, EF, FF, A1, 64, 14, 58, 00, 8B, 00, E8, 82, 59, EF, FF, 6A, EC, A1, 64, 14, 58, 00, 8B, 00, 8B, 40, 30, 50, E8, 34, 2F, E9, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, A1, 64, 14, 58, 00, 8B, 00, 8B, 40, 30, 50, E8, 64, 31, E9, FF, 8B, 0D, 98, 16, 58, 00, A1, 64, 14, 58, 00, 8B, 00, 8B, 15, F0, 1C, 57, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,521,664 bytes)

The file adobe flash player 2015.exe has been seen being distributed by the following URL.

Remove adobe flash player 2015.exe - Powered by Reason Core Security