File verdict·MT AI Engine assessment
Our call

Suspicious

Zero engine detections on a 6-year-old installer claiming Adobe but carrying an unverified signature and sandbox-observed process injection.

Signed but unverified · Adobe Inc.
Trust score55Caution
Adobe Installer
7.3 MB
b9a187b59c758ead00aa2e26774d
Antivirus engines
0 of 74 flagged
Code signing
Unverified: Adobe Inc.
Age
First seen 6y ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.

65%Confidence
High
Reasoning

Zero malicious detections across 69 reporting engines including 16 tier-1 clean reports rules out any named malware family. The signature claims Adobe Inc. but is unverified, removing any trusted-publisher protection. Sandbox execution recorded T1055 process injection, service creation, and direct-IP communication without DNS, which are classic evasion indicators. However, the file is six years old, has been submitted over 36 000 times, produced no malicious children, and contacted no known-bad hosts. These conflicting signals prevent a clean or malicious classification.

Analyst conclusion

No antivirus engine flagged the sample. The file carries an unverified Adobe signature and sandbox behaviour shows process injection plus direct-IP contact without domains. Prevalence is high and long-standing, yet the combination of spoofable signing and offensive MITRE techniques leaves the file in mixed-signals territory.

Detailed assessment

What We Detected

74 engines scanned the 7.6 MB Win32 EXE; none returned a malicious or suspicious label. The binary is signed with CN 'Adobe Inc.' but the signature is unverified. Sandbox analysis recorded three offensive MITRE techniques (T1055, T1543.003, T1562.001) and direct-IP contact to 15 addresses without domain resolution.

Threat Behavior

Process injection into explorer.exe and service-related activity were observed, yet no malicious dropped files, no malicious contacted hosts, and no sandbox malicious verdict were recorded. The file has existed since June 2020 with over 36 000 submissions and no engine consensus on any threat family.

What To Do Now

Do not execute the sample. Verify the file against an official Adobe distribution channel or obtain a properly code-signed installer from Adobe's site. If the file is required for legacy purposes, run it only in an isolated environment with network monitoring.

Key signals · 2

The strongest scan facts behind the verdict, preserved with their exact names and counts.

  1. 0 of 74 antivirus engines flagged the file.

  2. The hash has been submitted 36,935 times from 3,645 sources.

Points in its favour
  • Zero detections from 74 engines including 16 tier-1 clean reports
  • Common_old prevalence (3645 sources, 36935 submissions)
  • No malicious dropped children or contacted hosts
Points against
  • Unverified code signature claiming Adobe Inc.
  • Sandbox observed T1055 process injection
  • Direct-IP contact without DNS resolution
Recommended action

Treat as untrusted; obtain a verified Adobe installer from official sources before any execution.

What this file does

Observed actions and their security significance

  • High concern: Injected code into another process, a technique that can conceal execution.

  • High concern: Created or modified a system service, which can keep code running.

  • High concern: Changed an auto-start location that can make code run after sign-in or restart.

  • High concern: Attempted to impair or bypass security controls.

  • High concern: Manipulated how the operating system loads code, which can redirect execution.

  • Moderate concern: Runs hidden system commands (script or shell).

  • Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.

These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
20

Adversary techniques mapped to the MITRE ATT&CK framework.

T1012T1016· Network reconT1018T1036T1055· Process injectionT1057· Lists programsT1059· Runs commandsT1064T1071· Application protocolT1082· System reconT1095· Custom networkT1112T1497· Sandbox evasionT1518.001· Checks your AVT1543.003· Service installT1547.008· Auto-startT1562.001· Disables securityT1564.001· Hides artifactsT1573T1574.002· Execution hijack
Spawned processes
15
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
"C:\Users\<USER>\Desktop\software.exe"
$(unnamed)
C:\Windows\Explorer.EXE
$(unnamed)
%SAMPLEPATH%\Adobe Installer.exe
$(unnamed)
C:\Windows\System32\wuapihost.exe
$(unnamed)
C:\Program Files (x86)\Google1632_119729798\bin\updater.exe
$(unnamed)
C:\Program Files (x86)\Google3400_1763607481\bin\updater.exe
$(unnamed)
C:\Program Files (x86)\Google2468_2140960563\bin\updater.exe
+7 more processes captured.
Network activity
24
IP addresses20
  • 104.18.11.39
  • a83f:8110:700:0:ec3f:1c0:100:0
  • 104.18.10.39
  • 23.59.190.193
  • 192.168.0.66
  • 13.107.4.50
  • 20.80.129.13
  • a83f:8110:2e74:6578:7424:7800:c01f:0
  • 131.253.33.203
  • 192.168.0.61
+10 more
URLs4
  • http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e60f74d0bf521415
  • http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D
  • http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAbyTZ9NsHvX7K0Gf17ibCk%3D
  • http://crl.verisign.com/pca3.crl
Filesystem & mutexes
40
Files written15
  • C:\Users\<USER>\AppData\Local\Temp\CreativeCloud\ACC\AdobeDownload\HDInstaller.log
  • C:\Users\<USER>\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
  • C:\Users\user\AppData\Local\Temp\CreativeCloud\ACC\AdobeDownload\HDInstaller.log
  • C:\Users\user\AppData\Local\Temp
  • C:\Users\user\AppData\Local\Temp\CreativeCloud
+10 more
Files deleted15
  • C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
  • C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER15B5.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER177A.tmp.csv
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER1827.tmp.txt
+10 more
Mutexes created10
  • HDInstaller.log
  • Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
  • Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
  • Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
  • Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
+5 more
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • 0368bfe643c2d20053115f289fNever scanned
    never seen before
  • f35238da1e9a739caf6d928e9bNever scanned
    never seen before
  • a53a8237b1c0e9b2ec42cf94dcNever scanned
    never seen before
  • 4de77d2df7d285e4a2ba39264eNever scanned
    never seen before
  • 451b2bd009523777a1e4a6e838Never scanned
    never seen before
  • 99cb2a31fffc1b6cd7d709dd3dNever scanned
    never seen before
  • cbd79315982389cf75ab5e89f8Never scanned
    never seen before
  • eb3a677248868d530a29930c98Never scanned
    never seen before
  • 68095e77b9a1a8ae411a55315fNever scanned
    never seen before
  • 13c0e1644f4615865c6b345981Never scanned
    never seen before
No confirmed researcher-database hit
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\Explorer.EXE
  • DirectIpC2medium

    Sample contacted 15 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    104.18.11.39 · a83f:8110:700:0:ec3f:1c0:100:0 · 104.18.10.39
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash b9a187b59c75… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.

ent 7.18Unpacked
Section entropy5 sections
.text
6.55
.rdata
5.30
.data
2.62
.rsrc
5.47
.reloc
6.67
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
3,645
Hundreds of people have uploaded this — common.
Total submissions
36,935
Includes repeat uploads by the same source.
First seen
6y ago
Jun 30, 2020
Prevalence quadrant
Rare · New
Needs evidence-led scrutiny
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Often established software
File identity

Forensic fingerprint

File biography
First seen (VT)
Jun 30, 2020, 10:14 AM UTC
First seen (MalwareBazaar)
Last analysis (VT)
Jul 20, 2026, 10:31 PM UTC
Scanned here
Jul 22, 2026, 1:59 PM UTC
File name
Adobe Installer
Size
7.25 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
b9a187b59c758ead0022e50bbaae4133d2e37b769a054249afc0b6aa2e26774d
MD5
de70f0deed893bba56ccb78eafd59606
SHA-1
f351b0c2996a3573d36deab9b6b3961876189f71
PE imphash
e133890b059ac017fed069a78f415ebe
First seen (VT)
Jun 30, 2020, 10:14 AM UTC
Last analysis (VT)
Jul 20, 2026, 10:31 PM UTC
First scan (MalwareTips)
Jul 22, 2026, 10:58 AM UTC
Last scan (MalwareTips)
Jul 22, 2026, 1:59 PM UTC
Code signer
Adobe Inc.invalid
Community reputation
+15trusted
Behavior tags
direct-cpu-clock-accessoverlayinvalid-signaturedetect-debug-environmentruntime-modulesvia-torpeexesignedchecks-network-adapters
Frequently asked

Safety FAQ

Common questions about Adobe Installer, answered from the scan data above.

  • Adobe Installer is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • Adobe Installer is a software installer, about 7.3 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 74 antivirus engines we queried report Adobe Installer as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove Adobe Installer: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Adobe Installer file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • Adobe Installer claims a signer of Adobe Inc., but the signature is not verified — an unverified or broken signature can be forged, so it should not be trusted as proof of who made the file.
  • The SHA-256 hash of Adobe Installer is b9a187b59c758ead0022e50bbaae4133d2e37b769a054249afc0b6aa2e26774d, and its MD5 is de70f0deed893bba56ccb78eafd59606. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 22, 2026. Because a file's hash never changes, the identity of Adobe Installer is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Unknown files are temporarily processed and submitted to VirusTotal. MalwareTips does not retain the binary after processing. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.