adobe flash player.exe

Flash tolls

The executable adobe flash player.exe has been detected as malware by 9 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from bit.ly and multiple other hosts.
Publisher:
Flash tolls

Description:
Flash tolls

Version:
4.14.14.45

MD5:
201a5abec4ea03465be92fac756d7e82

SHA-1:
1114fe79b954dc82a4b56d24c5455d27444bfa08

SHA-256:
bd325c1ec554610bad07b6367d52f7e02caa5b946ae6b903c231481a4adbdfff

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
4/26/2024 3:23:44 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.55913
506

Arcabit
Trojan.Symmi.DDA69
1.0.0.541

Bitdefender
Gen:Variant.Symmi.55913
1.0.20.1300

Bkav FE
HW32.Packed
1.3.0.7237

Emsisoft Anti-Malware
Gen:Variant.Symmi.55913
8.15.09.17.10

F-Secure
Gen:Variant.Symmi.55913
11.2015-17-09_5

G Data
Gen:Variant.Symmi.55913
15.9.25

MicroWorld eScan
Gen:Variant.Symmi.55913
16.0.0.780

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

File size:
2.7 MB (2,818,560 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\downloads\adobe flash player.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:IbodR7cZ6BnEnTy3TNK2d8ZCFEVVoK9Fe1a6867eeYAqBXlpPySqabHN8XvM6:eoHYsFmMTNK9CFmVoyeg9liSzZ8XvT

Entry address:
0x5F9884

Entry point:
E9, 39, FB, FF, FF, B7, BB, A8, 91, EC, 74, 39, CC, A2, E1, 3C, 67, 86, AD, 15, 6D, F4, 13, 46, F7, 6E, C0, 93, B0, AD, 42, 11, 23, 32, 60, D5, C8, 94, 68, F1, 91, 57, A5, 8A, E7, 3D, 30, 32, 35, EE, 6F, 8C, B9, 48, 47, 14, 95, 0D, 44, 59, BB, 10, 67, 5A, 96, 81, 02, 24, 7B, 38, B6, B2, 46, 5E, 5C, A5, FA, BB, 38, 01, 56, EE, BB, 45, 6C, A4, 29, 16, 4D, 8D, B5, DB, E4, D7, 3D, 08, 1F, 9E, 11, BC, 64, 64, FF, 55, 0A, C1, BA, F8, EA, 7B, 3C, AF, A4, 91, 20, 8A, CE, 93, 10, 17, AC, B9, 08, 76, 2A, 9B, 3C, 55...
 
[+]

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
2.1 MB (2,158,592 bytes)

The file adobe flash player.exe has been seen being distributed by the following 2 URLs.

Remove adobe flash player.exe - Powered by Reason Core Security