flash player.exe

Flash Player

The application flash player.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.downward1227.info.
Product:
Flash Player

Version:
1.9.3.0

MD5:
2a50e34c4350d95cdac5cb7ad9bd46f6

SHA-1:
b625d73cd4fccd18011139cb32ab82e46b5c6bb4

SHA-256:
b52e56c6a184201a473ea86274466ec9a7478511883a880e05ecd093a5c7f9f4

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
1/13/2025 12:51:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.4
6353044

Agnitum Outpost
PUA.OutBrowse
7.1.1

avast!
PUP-gen [PUP]
150319-1

AVG
Potentially harmful program Downloader.DUA
2014.0.4311

Bitdefender
Gen:Variant.Application.Bundler.Outbrowse.4
1.0.20.435

Dr.Web
infected with Trojan.OutBrowse.115
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Outbrowse
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/28/2015

F-Secure
Gen:Variant.Application.Bundler
11.2015-28-03_7

G Data
Gen:Variant.Application.Bundler.Outbrowse
15.3.25

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

MicroWorld eScan
Gen:Variant.Application.Bundler.Outbrowse.4
16.0.0.261

NANO AntiVirus
Riskware.Win32.AirAdInstaller.doqort
0.30.8.659

Quick Heal
Adware.NSIS.OutBrowse.A
3.15.14.00

Sophos
Generic PUA ED
4.98

Trend Micro House Call
TROJ_GE.4223C86C
7.2.87

Trend Micro
TROJ_GE.4223C86C
10.465.28

Vba32 AntiVirus
AdWare.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.4150696
38552

File size:
1.1 MB (1,126,008 bytes)

Product version:
1.9.3.0

Copyright:
Flash Player

Original file name:
Ionic.Zip-2015Feb24-204601-9dd47b1b-2fdb-407a-a0bb-3c0dd8e92aea.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\flash player.exe

File PE Metadata
Compilation timestamp:
2/24/2015 3:46:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:NbSaE4mvt/qv0r7H5rLvKG7Y444L2iKDi:NbSv4mvMu7ZHKIY4tkDi

Entry address:
0x7604E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5934

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464.5 KB (475,648 bytes)

The file flash player.exe has been seen being distributed by the following URL.

Remove flash player.exe - Powered by Reason Core Security