adobe-flash-player.exe

Adobe flash player

The executable adobe-flash-player.exe has been detected as malware by 26 anti-virus scanners.
Publisher:
Adobe flash player

Product:
Adobe flash player

Version:
1.0

MD5:
2f8e2643e6829347a69e4ee851806a79

SHA-1:
ef470fa70d08dfbeb1ebdf9cdc2cf00b6d849fd4

SHA-256:
0fa6174ce59a6f53cabe753664b7c5426c4f48cd671b221e24f2987211cd6bc0

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
1/14/2025 9:52:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.383492
220

Agnitum Outpost
Trojan.DR.Agent
7.1.1

AhnLab V3 Security
Malware/Win32.Generic
2015.12.13

Avira AntiVirus
TR/Drop.Agent.885248
8.3.2.4

Arcabit
Trojan.Kazy.D5DA04
1.0.0.629

avast!
Win32:Dropper-gen [Drp]
2014.9-160629

AVG
Dropper.Generic9
2017.0.2698

Baidu Antivirus
Trojan.MSIL.Dropper
4.0.3.16629

Bitdefender
Gen:Variant.Kazy.383492
1.0.20.905

Comodo Security
UnclassifiedMalware
23732

Emsisoft Anti-Malware
Gen:Variant.Kazy.383492
8.16.06.29.01

ESET NOD32
JS/Fastliked
10.12712

Fortinet FortiGate
JS/Fastliked.C!tr
6/29/2016

F-Secure
Gen:Variant.Kazy.383492
11.2016-29-06_4

G Data
Gen:Variant.Kazy.383492
16.6.25

IKARUS anti.virus
VirTool.JS.Redichrextor
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.18088

Kaspersky
Trojan-Dropper.MSIL.BroExt
14.0.0.-15

McAfee
Artemis!2F8E2643E682
5600.6354

Microsoft Security Essentials
VirTool:JS/Redichrextor.A
1.1.12300.0

MicroWorld eScan
Gen:Variant.Kazy.383492
17.0.0.543

NANO AntiVirus
Trojan.Win32.Drop.cyiydr
1.0.10.5081

Panda Antivirus
Trj/CI.A
16.06.29.01

Qihoo 360 Security
Trojan.Generic
1.0.0.1077

Quick Heal
Trojan.Redichrextor.r4
6.16.14.00

ViRobot
Trojan.Win32.Z.Redichrextor.885248[h]
2014.3.20.0

File size:
864.5 KB (885,248 bytes)

Product version:
1.0

Copyright:
Copyright © 2014

Original file name:
Adobe flash player.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe-flash-player.exe

File PE Metadata
Compilation timestamp:
4/23/2014 9:26:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:4aDwF6f53iTFUf53iYwF6f53i6FUf53i:Hu6f5iUf5/u6f5/Uf5

Entry address:
0xB47FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.1880

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
714.5 KB (731,648 bytes)

The file adobe-flash-player.exe has been seen being distributed by the following URL.

Remove adobe-flash-player.exe - Powered by Reason Core Security