adobepdf.exe

The executable adobepdf.exe has been detected as malware by 21 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from env-6166603.jelastic.dogado.eu.
Version:
1.0.0.0

MD5:
6019694e2b3df9f4f9859e84813e6368

SHA-1:
02677e8362453056095530354dc203296f5d6b2d

SHA-256:
d1f958c6bf5c1de44010265414a5a547386f964ea5d1b7cb18b582411b31018a

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
7/12/2025 1:25:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2677844
348

Avira AntiVirus
TR/Rogue.856064.86
8.3.2.2

Arcabit
Trojan.Generic.D28DC54
1.0.0.425

avast!
Win32:Malware-gen
2014.9-160221

Bitdefender
Trojan.GenericKD.2677844
1.0.20.260

Emsisoft Anti-Malware
Trojan.GenericKD.2677844
8.16.02.21.12

Fortinet FortiGate
PossibleThreat.P0
2/21/2016

F-Secure
Trojan.GenericKD.2677844
11.2016-21-02_1

G Data
Trojan.GenericKD.2677844
16.2.25

K7 AntiVirus
Riskware
13.2017095

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.627

McAfee
Artemis!6019694E2B3D
5600.6482

Microsoft Security Essentials
Trojan:Win32/Trfijan.A
1.1.12002.0

MicroWorld eScan
Trojan.GenericKD.2677844
17.0.0.156

nProtect
Trojan.GenericKD.2677844
15.09.02.01

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.16219

Sophos
Mal/Generic-S
4.98

Total Defense
Heur/TrojanHorse.ZCIW!suspicious
37.1.62.1

Trend Micro
TROJ_GEN.R015C0DHR15
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic
43400

File size:
836 KB (856,064 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\adobepdf.exe

File PE Metadata
Compilation timestamp:
8/25/2015 12:24:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:b79SlLOpXFcgOpz3KNm3WdLVPUFEsZJsbXu/qNAdmDlZ5JU2erudY9q:nUlLOcdaNk6L49ZJsb1NamXcru

Entry address:
0x2D77D0

Entry point:
60, BE, 00, 10, 63, 35, 8D, BE, 00, 00, DE, FF, C7, 87, 10, EC, 25, 00, 1D, 22, 9F, 6E, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
732 KB (749,568 bytes)

The file adobepdf.exe has been seen being distributed by the following URL.

Remove adobepdf.exe - Powered by Reason Core Security