adobe_flash_player_2015_.exe

The executable adobe_flash_player_2015_.exe has been detected as malware by 13 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
MD5:
303f2e748f39b367ac443f1c42f55724

SHA-1:
17034d32359a602dd569002584e705039180f90a

SHA-256:
f285898dda17a490e19a4d841455fea4cf99a4c5abe8aa9de058a1576df74e77

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/26/2024 12:15:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.249255
5759710

Arcabit
Trojan.Graftor.D3CDA7
1.0.0.593

Bitdefender
Gen:Variant.Graftor.249255
1.0.20.1585

Emsisoft Anti-Malware
Gen:Variant.Graftor.249255
10.0.0.5366

ESET NOD32
Win32/TrojanDownloader.Banload.WRY trojan
7.0.302.0

F-Secure
Gen:Variant.Graftor.249255
5.15.21

G Data
Gen:Variant.Graftor.249255
15.11.25

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1125

McAfee
Trojan.Artemis!303F2E748F39
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.209.2659.0

MicroWorld eScan
Gen:Variant.Graftor.249255
16.0.0.951

Norman
Gen:Variant.Graftor.249255
28.10.2015 12:55:53

Qihoo 360 Security
QVM05.1.Malware.Gen
1.0.0.1077

File size:
1.5 MB (1,606,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe_flash_player_2015_.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:0ENuwwTTuD8WDAwgq0/otS86qS5Mrr+MCWXFVYNNGlL4TE2vRsPZtN/TSlTU+L0l:JNCqIo0JqNrruWMHE2psPZtN/TYTPq

Entry address:
0x153030

Entry point:
55, 8B, EC, 83, C4, F0, B8, C8, 29, AB, 06, E8, 04, 3B, EB, FF, 68, C8, 30, AB, 06, 6A, 00, 6A, 00, E8, B2, 3D, EB, FF, E8, 4D, 3F, EB, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, D0, 05, AC, 06, 8B, 00, E8, 7A, 2A, F1, FF, A1, D0, 05, AC, 06, 8B, 00, E8, EA, 28, F1, FF, 6A, EC, A1, D0, 05, AC, 06, 8B, 00, 8B, 40, 30, 50, E8, 0C, 47, EB, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, A1, D0, 05, AC, 06, 8B, 00, 8B, 40, 30, 50, E8, 24, 49, EB, FF, 8B, 0D, D4, 05, AC, 06, A1, D0, 05, AC, 06, 8B, 00, 8B, 15, 00, 0F, AB, 06, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,384,960 bytes)

The file adobe_flash_player_2015_.exe has been seen being distributed by the following URL.

Remove adobe_flash_player_2015_.exe - Powered by Reason Core Security