adobe flash player 2015.exe

The executable adobe flash player 2015.exe has been detected as malware by 25 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from bit.ly and multiple other hosts.
MD5:
a759e1eec5f0cdcdad624bebfe321ed1

SHA-1:
180a52c1af22085131afdf2f86f7bdd1411dbcb2

SHA-256:
87f77526996e392b810802a52840fbe236c9e74ab67a7040360da169bfbdadc0

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
7/9/2025 5:46:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2784740
465

Avira AntiVirus
TR/Dldr.Banload.755
8.3.2.2

Arcabit
Trojan.Generic.D2A7DE4
1.0.0.582

avast!
Win32:Banker-MJB [Trj]
2014.9-151028

AVG
Luhe.Fiha.A
2016.0.2943

Bitdefender
Trojan.GenericKD.2784740
1.0.20.1505

Emsisoft Anti-Malware
Trojan.GenericKD.2784740
8.15.10.28.12

ESET NOD32
Win32/TrojanDownloader.Banload.WOX (variant)
9.12416

Fortinet FortiGate
W32/Banload.CXCM!tr.dldr
10/28/2015

F-Secure
Trojan.GenericKD.2784740
11.2015-28-10_4

G Data
Trojan.GenericKD.2784740
15.10.25

IKARUS anti.virus
Trojan.Agent
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.210.17554

Kaspersky
Trojan-Downloader.Win32.Banload
14.0.0.1210

Malwarebytes
Trojan.Banload.GGL
v2015.10.28.12

McAfee
Artemis!A759E1EEC5F0
5600.6599

Microsoft Security Essentials
TrojanDownloader:Win32/Banload.BEW
1.1.12101.0

MicroWorld eScan
Trojan.GenericKD.2784740
16.0.0.903

NANO AntiVirus
Trojan.Win32.Banload.dxtvvi
0.30.26.3947

nProtect
Trojan.GenericKD.2784740
15.10.16.01

Panda Antivirus
Trj/CI.A
15.10.28.12

Reason Heuristics
Threat.Win.Reputation.IMP
15.11.19.19

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R0EAC0DJF15
10.465.28

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
1.1 MB (1,140,736 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe flash player 2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xxl38VsW5AqJru81ldIpTk0S9Cr2cn4eUKOA7UoGEDTU+klg:xdeldIG0Nr2b8TP+

Entry address:
0xE62E4

Entry point:
55, 8B, EC, 83, C4, F0, B8, A4, 5D, 4E, 00, E8, CC, 05, F2, FF, 68, 7C, 63, 4E, 00, 6A, 00, 6A, 00, E8, 26, 08, F2, FF, E8, A1, 09, F2, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, 84, 04, 4F, 00, 8B, 00, E8, A2, 9A, F7, FF, A1, 84, 04, 4F, 00, 8B, 00, E8, 12, 99, F7, FF, 6A, EC, A1, 84, 04, 4F, 00, 8B, 00, 8B, 40, 30, 50, E8, 20, 11, F2, FF, 0D, 80, 00, 00, 00, 50, 6A, EC, A1, 84, 04, 4F, 00, 8B, 00, 8B, 40, 30, 50, E8, 20, 13, F2, FF, 8B, 0D, F8, 06, 4F, 00, A1, 84, 04, 4F, 00, 8B, 00, 8B, 15, 50, 3F, 4E, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
917 KB (939,008 bytes)

The file adobe flash player 2015.exe has been seen being distributed by the following 3 URLs.

Remove adobe flash player 2015.exe - Powered by Reason Core Security