adobe flash player-2015.exe

The executable adobe flash player-2015.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com and multiple other hosts.
MD5:
710f9a2f1289452c9a819e11d44ce91d

SHA-1:
d30ed80f18e67b05859462dc5db9af569b3e24f3

SHA-256:
905acfb829da02bfbd5924579e835f6623d198178665dd7d96c0a1aa10fdd757

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
5/1/2024 8:44:03 PM UTC  (today)

Scan engine
Detection
Engine version

Arcabit
Trojan.Graftor.D3CD1D
1.0.0.593

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.151114

Bitdefender
Gen:Variant.Graftor.249117
1.0.20.1590

Emsisoft Anti-Malware
Gen:Variant.Graftor.249117
8.15.11.14.04

ESET NOD32
Win32/TrojanDownloader.Banload.WRR (variant)
9.12559

F-Secure
Gen:Variant.Graftor.249117
11.2015-14-11_7

G Data
Gen:Variant.Graftor.249117
15.11.25

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1124

MicroWorld eScan
Gen:Variant.Graftor.249117
16.0.0.954

Qihoo 360 Security
Win32/Trojan.e6d
1.0.0.1077

Sophos
Mal/Generic-S
4.98

File size:
1.5 MB (1,568,768 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe flash player-2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:UlM1FEsOrQSWDAu1eKYwZhPe4DPvivH+wjVDiEv/M+ROFTSqh4EfHbwYyWGYGVJ/:cMFhHZhP7DyfrjpDM+swHVrTPRT

Entry address:
0x14B29C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 64, AC, AD, 00, E8, 30, B8, EB, FF, 68, 34, B3, AD, 00, 6A, 00, 6A, 00, E8, DE, BA, EB, FF, E8, 71, BC, EB, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, 44, 84, AE, 00, 8B, 00, E8, E6, 9B, F1, FF, A1, 44, 84, AE, 00, 8B, 00, E8, 56, 9A, F1, FF, 6A, EC, A1, 44, 84, AE, 00, 8B, 00, 8B, 40, 30, 50, E8, F8, C3, EB, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, A1, 44, 84, AE, 00, 8B, 00, 8B, 40, 30, 50, E8, 10, C6, EB, FF, 8B, 0D, 48, 84, AE, 00, A1, 44, 84, AE, 00, 8B, 00, 8B, 15, 24, 92, AD, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,352,704 bytes)

The file adobe flash player-2015.exe has been seen being distributed by the following 3 URLs.

Remove adobe flash player-2015.exe - Powered by Reason Core Security