adobe-flash-player.exe

The application adobe-flash-player.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdnus.ironcdn.com.
MD5:
366174f655be0eacf2111cb43d2dce71

SHA-1:
4cea5d008374520fbe6e4e8b1aa4892c4603fd48

SHA-256:
095f4283f3a053ab3504fb1367730c423a86513fd299b20dd7f15f13d7d61f57

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/4/2024 7:31:48 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.BA (variant)
9.9630

F-Prot
W32/InstallCore.V2.gen
v6.4.7.1.166

herdProtect (fuzzy)
2015.10.31.4

K7 AntiVirus
Unwanted-Program
13.176.11637

Malwarebytes
v2015.09.04.10

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15902

Sophos
InstallCore ToDownload
4.98

Vba32 AntiVirus
Adware.InstallCore.gen
3.12.24.3

File size:
1 MB (1,100,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\Music\programs\adobe-flash-player.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:tG9UOZrfEK+v4fDsH8KYXOnOZ8stpVuGZW69S/Fyx7XJ62jTz:tsEK0IDsczqstpVuGR9CFyx7XJBX

Entry address:
0xCD290

Entry point:
55, 8B, EC, 83, C4, F0, B8, 8C, 24, 41, 00, E8, E7, D8, FF, FF, 25, 78, F1, 45, 00, 8B, C0, FF, 25, 74, F1, 45, 00, 8B, C0, FF, 25, 70, F1, 45, 00, 8B, C0, FF, 25, 6C, F1, 45, 00, 8B, C0, FF, 25, D8, F1, 45, 00, 8B, C0, FF, 25, 68, F1, 45, 00, 8B, C0, FF, 25, 64, F1, 45, 00, 8B, C0, FF, 25, 60, F1, 45, 00, 8B, C0, FF, 25, F0, F1, 45, 00, 8B, C0, FF, 25, EC, F1, 45, 00, 8B, C0, FF, 25, E8, F1, 45, 00, 8B, C0, FF, 25, 5C, F1, 45, 00, 8B, C0, FF, 25, 58, F1, 45, 00, 8B, C0, FF, 25, 00, F2, 45, 00, 8B, C0, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
837.5 KB (857,600 bytes)

The file adobe-flash-player.exe has been seen being distributed by the following URL.

Remove adobe-flash-player.exe - Powered by Reason Core Security