adobe_flash_player.exe

The application adobe_flash_player.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com and multiple other hosts.
MD5:
a35ff2855c27cc919014dfda94ad0d19

SHA-1:
b2dd968509246f9b8115b4b4e4398876eb80e25b

SHA-256:
ee4e59391c8ecd0af5e2dc912d6b75983843128e9b18f3ca5321c6277ce5c875

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 7:34:02 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.DP.0PW@ayhhZgfG
595

Arcabit
Trojan.Heur.DP.E4F343
1.0.0.425

Bitdefender
Gen:Trojan.Heur.DP.0PW@ayhhZgfG
1.0.20.850

Emsisoft Anti-Malware
Gen:Trojan.Heur.DP.0PW@ayhhZgfG
8.15.06.19.07

G Data
Gen:Trojan.Heur.DP.0PW@ayhhZgfG
15.6.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.9.5.0

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Win.Reputation
15.12.27.15

Trend Micro House Call
TROJ_GEN.R047H09F215
7.2.170

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
1.8 MB (1,902,592 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe_flash_player.exe

File PE Metadata
Compilation timestamp:
5/31/2015 6:10:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:OlySo1begTVUYpElw3R79NtTbKNHL34De1:0Do9Elw3R5NtTuNkE

Entry address:
0xD54B8

Entry point:
55, 8B, EC, B9, 07, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 9C, DB, 4C, 00, E8, 27, 4F, F3, FF, 33, C0, 55, 68, FC, 56, 4D, 00, 64, FF, 30, 64, 89, 20, B9, 05, 00, 00, 00, B2, 01, A1, F0, D1, 4C, 00, E8, 98, 7F, FF, FF, A3, 48, 42, 4E, 00, A1, 48, 42, 4E, 00, 8B, 50, 04, 8D, 45, EC, B9, 18, 57, 4D, 00, E8, C2, 21, F3, FF, 8B, 45, EC, B2, 01, E8, A8, 57, F4, FF, 84, C0, 0F, 85, C1, 01, 00, 00, 33, D2, 55, 68, 53, 55, 4D, 00, 64, FF, 32, 64, 89, 22, 33, C9, B2, 01, A1, B8, 6D, 4C, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
850.5 KB (870,912 bytes)

The file adobe_flash_player.exe has been seen being distributed by the following 3 URLs.

Remove adobe_flash_player.exe - Powered by Reason Core Security