adobe flash player-2015.exe

BUILDER ASKIS

The executable adobe flash player-2015.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
Publisher:
BUILDER ASKIS

Description:
BUILDER ASKIS

Version:
101.88.99.1236

MD5:
db649ed3178b3afc4ac92dc5dee8ba64

SHA-1:
dde52c21db7c3d7edbcfbcdd55fa45cb4aed0bfb

SHA-256:
af94dd07a7d5dad672e0be70f41939cf8cc38de81f95b16687659f027473ce44

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/25/2024 11:22:40 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.56650
5717851

Arcabit
Trojan.Symmi.DDD4A
1.0.0.527

Bitdefender
Gen:Variant.Symmi.56650
1.0.20.1290

Emsisoft Anti-Malware
Gen:Variant.Symmi.56650
8.15.09.15.07

ESET NOD32
Win32/TrojanDownloader.Banload.WMB trojan
7.0.302.0

F-Secure
Gen:Variant.Symmi.56650
5.14.151

G Data
Gen:Variant.Symmi.56650
15.9.25

MicroWorld eScan
Gen:Variant.Symmi.56650
16.0.0.774

Norman
Gen:Variant.Symmi.56650
04.08.2015 10:30:46

Reason Heuristics
Threat.Win.Reputation.IMP
15.11.27.23

File size:
3.1 MB (3,273,216 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Romeno (Romênia)

Common path:
C:\users\{user}\downloads\adobe flash player-2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:R6tHS55CiUkRllWG4moX7sBHn3iPNluSYQxdJZ2UvTP7TCi:R6hhiRTUG+XwBHngY4Zhq

Entry address:
0x2BF90C

Entry point:
55, 8B, EC, 83, C4, F0, B8, DC, ED, 6B, 00, E8, 50, 77, D4, FF, 68, A4, F9, 6B, 00, 6A, 00, 6A, 00, E8, 36, 7C, D4, FF, E8, C1, 7D, D4, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, 80, E7, 6C, 00, 8B, 00, E8, 42, 8A, DB, FF, A1, 80, E7, 6C, 00, 8B, 00, E8, B2, 88, DB, FF, 6A, EC, A1, 80, E7, 6C, 00, 8B, 00, 8B, 40, 30, 50, E8, 90, 85, D4, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, A1, 80, E7, 6C, 00, 8B, 00, 8B, 40, 30, 50, E8, C8, 87, D4, FF, 8B, 0D, 48, EA, 6C, 00, A1, 80, E7, 6C, 00, 8B, 00, 8B, 15, D8, D2, 6B, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.7 MB (2,877,952 bytes)

The file adobe flash player-2015.exe has been seen being distributed by the following URL.

Remove adobe flash player-2015.exe - Powered by Reason Core Security