adobe_flash_player_2015.exe

The executable adobe_flash_player_2015.exe has been detected as malware by 17 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from bit.ly and multiple other hosts.
Version:
15.0.0.0

MD5:
94bec38d4997b12c147297f2f3d69f83

SHA-1:
08fac266f1c403c3a171b3dee64661406305d16b

SHA-256:
dde2116e85420de86259c5c816d4d20eef64de2e1d76a20d9bbaf2e2ef1e98cb

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
7/8/2025 6:48:31 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.737350
490

Avira AntiVirus
TR/Dldr.Agent.223232.5
8.3.2.2

Arcabit
Trojan.Kazy.DB4046
1.0.0.568

avast!
MSIL:Banker-DO [Trj]
2014.9-151002

AVG
Downloader.MSIL
2016.0.2968

Bitdefender
Gen:Variant.Kazy.737350
1.0.20.1375

Emsisoft Anti-Malware
Gen:Variant.Kazy.737350
8.15.10.02.10

ESET NOD32
MSIL/TrojanDownloader.Banload.EW (variant)
9.12347

Fortinet FortiGate
MSIL/Banload.EU!tr.dldr
10/2/2015

F-Secure
Gen:Variant.Kazy.737350
11.2015-02-10_6

G Data
Gen:Variant.Kazy.737350
15.10.25

IKARUS anti.virus
Trojan-Downloader.MSIL.Banload
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.210.17409

Malwarebytes
Trojan.Banker.LRD
v2015.10.02.10

McAfee
Artemis!94BEC38D4997
5600.6624

MicroWorld eScan
Gen:Variant.Kazy.737350
16.0.0.825

Sophos
Mal/Generic-S
4.98

File size:
218 KB (223,232 bytes)

Product version:
15.0.0.0

Copyright:
Copyright © 2015

Original file name:
GEPX.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe_flash_player_2015.exe

File PE Metadata
Compilation timestamp:
9/30/2015 3:14:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:B5zJ+lM+sEvWfROJLhfJpreQ00ws/R3b/rz3qhO32GhNvHuxofifmZzhXX3BBehz:MWROJNhpeBUDnq+2GhN/bBAw9XfXI

Entry address:
0x36CDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
211.5 KB (216,576 bytes)

The file adobe_flash_player_2015.exe has been seen being distributed by the following 3 URLs.

Remove adobe_flash_player_2015.exe - Powered by Reason Core Security