adobeflashplayer_10.7.exe

The executable adobeflashplayer_10.7.exe has been detected as malware by 25 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from update10.adobe-flash-player10.from-nm.com.
MD5:
448cfcfcbffc59a6121f55949c3a5b24

SHA-1:
385c2fb56cea501efb50736c9cdf1a3e50011979

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
5/16/2024 8:50:42 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Securisk
2011.06.10

Avira AntiVirus
TR/Agent.33587240
7.11.9.132

avast!
Win32:Renosa-I
2014.9-160116

AVG
Generic22
2017.0.2863

Bitdefender
Trojan.Generic.6087526
1.0.20.80

Comodo Security
TrojWare.Win32.Trojan.Agent.Gen
9009

Dr.Web
Trojan.Fakealert.21346
9.0.1.016

Emsisoft Anti-Malware
Trojan.Win32.FakeAV!IK
8.16.01.16.12

ESET NOD32
Win32/Kryptik.ODJ (variant)
10.6194

G Data
Trojan.Generic.6087526
16.1.22

IKARUS anti.virus
Trojan.Win32.FakeAV
t3scan.1.1.104.0

K7 AntiVirus
Trojan
13.105.4792

McAfee
FakeAlert-Rena.j
5600.6519

Microsoft Security Essentials
Rogue:Win32/FakeRean
1.163.1557.0

Norman
W32/FakeAV.AEDB
11.20160116

nProtect
Trojan.Generic.6087526
11.06.09.01

Panda Antivirus
Generic Trojan
16.01.16.12

Quick Heal
(Suspicious) - DNAScan
1.16.11.00

Rising Antivirus
Trojan.Win32.Generic.128836ED
23.00.65.16114

Sophos
Mal/FakeAV-LZ
4.66

SUPERAntiSpyware
Trojan.Agent/Gen-Frauder
9383

Trend Micro House Call
TROJ_FAKEAL.SMQP
7.2.16

Trend Micro
TROJ_FAKEAL.SMQP
10.465.16

Vba32 AntiVirus
Trojan.FakeAV.dfbg
3.12.16.1

VIPRE Antivirus
FraudTool.Win32.FakeRean.i
9536

File size:
328 KB (335,872 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\florian\eigene dateien\downloads\adobeflashplayer_10.7.exe

File PE Metadata
Compilation timestamp:
4/13/2008 8:33:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:1lWqlVVhJA/UfwA2I5H+qtTqnXA0m0gxP9X5vt7Ha2eXUcN/LO3D:jVVhgUoMXJqnw0XgDJvtTa13FO3D

Entry address:
0x5E68

Entry point:
6A, 60, 68, 15, 48, 40, 00, E8, 5B, 00, 00, 00, BF, 5E, 00, DA, 96, E7, AE, EF, A3, 87, 00, 00, 73, A8, F6, CC, 00, 5B, 00, 00, AC, 00, 00, 7B, B6, CE, F0, C9, 63, 00, 00, 00, 00, AD, E9, E0, 68, 00, E9, 95, 00, 00, 00, EC, 6F, 00, 7E, 00, 00, 75, 00, AF, 00, 72, 00, 00, BE, 00, 9A, 00, C0, ED, 00, 00, A7, 00, 00, EE, C5, 61, 54, F2, D8, F0, E4, 00, 00, 00, 00, 00, 00, 00, F6, E8, 68, 00, 7B, 6A, A4, FC, 00, 55, 8B, EC, 83, C4, E8, 68, 83, 88, 00, 00, 51, 68, EE, DA, 3D, 1B, 68, 75, EE, 4F, BD, 6A, F0, 8D...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
240 KB (245,760 bytes)

The file adobeflashplayer_10.7.exe has been seen being distributed by the following URL.

Remove adobeflashplayer_10.7.exe - Powered by Reason Core Security