adobe-flash-player.exe

The application adobe-flash-player.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdnus.ironcdn.com and multiple other hosts.
MD5:
9640a361cbc8abd0a186b12a22eeaa74

SHA-1:
37b245f97a82e06d27a46650b62934fd7b13d7c3

SHA-256:
bd8cd97df040c98eddf74a8f05c77332453eb08ceb753fb346f7c18cdfbbc729

Scanner detections:
22 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 8:35:10 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen6
7.11.144.142

avast!
Win32:InstallCore-FK [PUP]
2014.9-150111

AVG
MalSign.InstallCore
2016.0.3232

Bitdefender
Gen:Variant.Application.InstallCore.13
1.0.20.55

Bkav FE
HW32.Laneul
1.3.0.4959

Clam AntiVirus
W32S.Adware.Installcore-1
0.98/18355

Comodo Security
UnclassifiedMalware
18139

Dr.Web
Adware.MediaFinder.2
9.0.1.011

Emsisoft Anti-Malware
Riskware.Win32.InstallCore.AMN!A2
8.15.01.11.08

ESET NOD32
Win32/InstallCore.AE (variant)
9.7353

Fortinet FortiGate
Riskware/InstallCore
1/11/2015

F-Prot
W32/InstallCore.V2.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Application.InstallCore.13
11.2015-11-01_1

G Data
Gen:Variant.Application.InstallCore.13
15.1.22

K7 AntiVirus
Unwanted-Program
13.145.7426

Kaspersky
not-a-virus:WebToolbar.Win32.InstallCore
14.0.0.2656

Panda Antivirus
PUP/MultiToolbar.A
15.01.11.08

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15109

Trend Micro House Call
TROJ_GEN.R0C1B01B214
7.2.11

Vba32 AntiVirus
Malware-Cryptor.InstallCore.9
3.12.18.5

VIPRE Antivirus
Click run software
28442

File size:
1 MB (1,079,272 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe-flash-player.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:pmGeWVzUZHdcTxS+9JciHHDsSc5lwOKYlD2ts6RojS:EGeazKOTxS+nsfwOKYMR

Entry address:
0xC9560

Entry point:
55, 8B, EC, 83, C4, F0, B8, 8C, 24, 41, 00, E8, B6, DB, FF, FF, 46, 00, 01, 00, 00, 00, 8B, C3, E8, 8A, FD, FF, FF, 8B, DF, 81, FB, E4, 85, 46, 00, 75, A7, 8B, 44, 24, 04, 33, D2, 89, 10, 83, 7C, 24, 0C, 00, 74, 19, 8B, 44, 24, 04, 8B, 54, 24, 08, 89, 10, 8B, 44, 24, 0C, 2B, 44, 24, 08, 8B, 54, 24, 04, 89, 42, 04, 83, C4, 14, 5D, 5F, 5E, 5B, C3, 53, 56, 57, 55, 83, C4, F4, 89, 4C, 24, 04, 89, 14, 24, 8B, D0, 8B, EA, 81, E5, 00, F0, FF, FF, 03, 14, 24, 81, C2, FF, 0F, 00, 00, 81, E2, 00, F0, FF, FF, 89, 54...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
817.5 KB (837,120 bytes)

The file adobe-flash-player.exe has been seen being distributed by the following 2 URLs.

http://cdnus.ironcdn.com/.../Adobe-Flash-Player.exe

Remove adobe-flash-player.exe - Powered by Reason Core Security