novo adobe flash player 2015.exe

The executable novo adobe flash player 2015.exe has been detected as malware by 15 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
MD5:
0329cea1a9ea0e46620142f08038db8e

SHA-1:
aa4fde314f00ade8cd9648d087cac0e6e97d79fb

SHA-256:
9ff9115648a37ca7614c179daf820acd6ac41d773a948cad59428bd3cc42f5bc

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/16/2024 11:43:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.198008
5729989

Arcabit
Trojan.Graftor.D30578
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150619

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.15619

Bitdefender
Gen:Variant.Graftor.198008
1.0.20.850

Emsisoft Anti-Malware
Gen:Variant.Graftor.198008
10.0.0.5366

ESET NOD32
Win32/TrojanDownloader.Banload.VXF trojan
7.0.302.0

Fortinet FortiGate
W32/Banload.VXF!tr.dldr
6/19/2015

F-Secure
Gen:Variant.Graftor.198008
5.14.151

G Data
Gen:Variant.Graftor.198008
15.6.25

McAfee
Trojan.Artemis!0329CEA1A9EA
17.6.569.0

MicroWorld eScan
Gen:Variant.Graftor.198008
16.0.0.510

Norman
Gen:Variant.Graftor.198008
02.06.2015 14:23:46

Panda Antivirus
Trj/CI.A
15.06.19.07

Sophos
Virus 'Mal/Behav-130'
5.15

File size:
645 KB (660,480 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\novo adobe flash player 2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:WbsYWIbWvGHrjFKNTl759H5ywTLs6ADdwiOX3eQHShASTCKK:WIVIEGHrpK53DyoADdw/XuQuT

Entry address:
0x7BC88

Entry point:
55, 8B, EC, 83, C4, F0, B8, F0, B8, 47, 00, E8, A4, A4, F8, FF, A1, 28, DF, 47, 00, 8B, 00, E8, C0, AE, FD, FF, A1, 28, DF, 47, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, C4, E0, 47, 00, A1, 28, DF, 47, 00, 8B, 00, 8B, 15, 60, AD, 47, 00, E8, B5, AE, FD, FF, A1, 28, DF, 47, 00, 8B, 00, E8, 29, AF, FD, FF, E8, 24, 81, F8, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
491.5 KB (503,296 bytes)

The file novo adobe flash player 2015.exe has been seen being distributed by the following URL.

Remove novo adobe flash player 2015.exe - Powered by Reason Core Security