adobe_flash_player_18092015.exe

The executable adobe_flash_player_18092015.exe has been detected as malware by 15 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from bit.ly and multiple other hosts.
MD5:
8fa1e3a9100e82d3fa7d6d6116f7254a

SHA-1:
578ad4f7a4403774ca7eabd0deecacc9e18b162d

SHA-256:
76e632f4c15363ba5ee6b36d84e799ca8bbdfb973bb9ca8e1c2f660ff5824cc9

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/25/2024 5:59:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.56028
503

Arcabit
Trojan.Symmi.DDADC
1.0.0.545

Bitdefender
Gen:Variant.Symmi.56028
1.0.20.1310

Bkav FE
HW32.Packed
1.3.0.7237

Emsisoft Anti-Malware
Gen:Variant.Symmi.56028
8.15.09.19.05

ESET NOD32
Win32/TrojanDownloader.Banload.WML (variant)
9.12277

F-Secure
Gen:Variant.Symmi.56028
11.2015-19-09_7

G Data
Gen:Variant.Symmi.56028
15.9.25

IKARUS anti.virus
Virus.Win32.CryptExe
t3scan.1.9.5.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1401

MicroWorld eScan
Gen:Variant.Symmi.56028
16.0.0.786

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
9.15.14.00

SUPERAntiSpyware
Trojan.Agent/Gen-Banload
9620

Vba32 AntiVirus
Trojan.Svchost.5505
3.12.26.4

File size:
954.6 KB (977,561 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe_flash_player_18092015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:GG6azbHz8XmXfjp7vGI0OGjR9DGBCLYH6DH8O6:H6eKmXbprGlR9WCkH6DH+

Entry address:
0x1E2000

Entry point:
60, 66, 8B, EE, 66, C1, D0, BD, 4D, 48, FC, 45, 66, D3, CD, 66, 81, E5, F1, 30, 75, 02, D3, D0, 4B, 8B, DF, 7C, 05, BB, 77, 92, A1, ED, 71, 02, 1B, E9, EB, 0F, 78, 83, C4, 04, 7C, 19, 7D, 17, 77, E8, 0C, 00, 00, 00, 7C, 72, F8, 73, F6, 7D, E8, E8, FF, FF, FF, EA, 83, 04, 24, 06, C3, C1, F8, 86, EB, 0F, 79, 83, C4, 04, 74, 19, 75, 17, 7B, E8, 0C, 00, 00, 00, 7A, 7A, F8, 7B, F6, E9, E8, E8, FF, FF, FF, 9A, 83, 04, 24, 06, C3, 40, E8, 0B, 00, 00, 00, 72, 74, 16, 75, 14, 7A, 74, 0E, 75, 0C, 7A, 83, C4, 04, 72...
 
[+]

Code size:
2 MB (2,055,680 bytes)

The file adobe_flash_player_18092015.exe has been seen being distributed by the following 3 URLs.

Remove adobe_flash_player_18092015.exe - Powered by Reason Core Security