adobe flash player 2015.exe

WhatsApp

The executable adobe flash player 2015.exe has been detected as malware by 29 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from bit.ly and multiple other hosts.
Publisher:
WhatsApp

Description:
WhatsApp

Version:
109.95.94.1241

MD5:
08c62250ba3b8a755f9b00201d062957

SHA-1:
de7b7417d942c538d3373f4e9b7ad22c5da4fac6

SHA-256:
426544d874e068564edf153afdc2beee7b049aaa4b94a8bc9eabebf6c62d7d5e

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
7/8/2025 12:13:04 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Samca
7.1.1

AhnLab V3 Security
Malware/Win32.Generic
2015.11.08

Avira AntiVirus
TR/Samca.A.215
8.3.2.2

Arcabit
Trojan.Generic.DE6822C
1.0.0.590

avast!
Win32:Malware-gen
2014.9-160114

AVG
Generic36
2017.0.2864

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.16114

Bitdefender
Trojan.Generic.15106604
1.0.20.70

Bkav FE
HW32.Packed
1.3.0.7383

Emsisoft Anti-Malware
Trojan.Generic.15106604
8.16.01.14.04

ESET NOD32
Win32/TrojanDownloader.Banload.WOK (variant)
10.12532

Fortinet FortiGate
W32/Banload.WOK!tr.dldr
1/14/2016

F-Secure
Trojan.Generic.15106604
11.2016-14-01_5

G Data
Trojan.Generic.15106604
16.1.25

IKARUS anti.virus
Trojan-Downloader.Banload
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.212.17783

Kaspersky
Trojan-Downloader.Win32.Banload
14.0.0.817

McAfee
Artemis!08C62250BA3B
5600.6520

Microsoft Security Essentials
TrojanDownloader:Win32/Banload.BFC
1.1.12205.0

MicroWorld eScan
Trojan.Generic.15106604
17.0.0.42

NANO AntiVirus
Trojan.Win32.Banload.dyjkjp
0.30.26.4437

nProtect
Trojan.Generic.15106604
15.11.06.01

Panda Antivirus
Generic Suspicious
16.01.14.04

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R03FC0DJM15
10.465.14

Vba32 AntiVirus
Trojan.Svchost.5505
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
45084

ViRobot
Trojan.Win32.S.Agent.1502541.A[h]
2014.3.20.0

Zillya! Antivirus
Worm.AutoRun.Win32.119408
2.0.0.2497

File size:
1.4 MB (1,502,541 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Ucraniano (Ucrânia)

Common path:
C:\users\{user}\downloads\adobe flash player 2015.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xq2j1JpB+GM2vMcZb83xlBQXUV1Ff04d5q8s+ffJ/lCk56c57:xhaGMn13xlBqI5F57fT2cZ

Entry address:
0x31E000

Entry point:
60, BA, BD, 26, 94, C2, 72, 01, 4E, 1B, D1, F8, 4F, 79, 02, D3, FF, 4E, 4B, 85, DE, 4B, 0F, 85, 02, 00, 00, 00, 85, DF, 76, 03, 66, D3, C3, 87, DF, E8, 09, 00, 00, 00, 73, 83, 04, 24, 06, C3, EB, 0F, E9, 83, C4, 04, 7A, F8, 7B, F6, 7F, E8, EB, FF, FF, FF, 75, 78, F8, 79, F6, 72, D3, EE, EB, 0B, 79, 83, 04, 24, 04, C3, 7C, 0E, 7D, 0C, 7B, 7C, F9, 7D, F7, 75, E8, EC, FF, FF, FF, 7A, EB, F8, EA, 4E, 78, 0E, 79, 0C, 79, 7E, 17, 7F, 15, 9A, E8, 07, 00, 00, 00, EB, EB, F8, 74, EB, F0, 7E, 83, C4, 04, 7C, F8, 7D...
 
[+]

Code size:
3.2 MB (3,350,528 bytes)

The file adobe flash player 2015.exe has been seen being distributed by the following 2 URLs.

Remove adobe flash player 2015.exe - Powered by Reason Core Security