Suspicious
Zero engine detections on a 6-year-old installer claiming Adobe but carrying an unverified signature and sandbox-observed process injection.
b9a187b59c758ead00…aa2e26774dThe reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Zero malicious detections across 69 reporting engines including 16 tier-1 clean reports rules out any named malware family. The signature claims Adobe Inc. but is unverified, removing any trusted-publisher protection. Sandbox execution recorded T1055 process injection, service creation, and direct-IP communication without DNS, which are classic evasion indicators. However, the file is six years old, has been submitted over 36 000 times, produced no malicious children, and contacted no known-bad hosts. These conflicting signals prevent a clean or malicious classification.
No antivirus engine flagged the sample. The file carries an unverified Adobe signature and sandbox behaviour shows process injection plus direct-IP contact without domains. Prevalence is high and long-standing, yet the combination of spoofable signing and offensive MITRE techniques leaves the file in mixed-signals territory.
What We Detected
74 engines scanned the 7.6 MB Win32 EXE; none returned a malicious or suspicious label. The binary is signed with CN 'Adobe Inc.' but the signature is unverified. Sandbox analysis recorded three offensive MITRE techniques (T1055, T1543.003, T1562.001) and direct-IP contact to 15 addresses without domain resolution.
Threat Behavior
Process injection into explorer.exe and service-related activity were observed, yet no malicious dropped files, no malicious contacted hosts, and no sandbox malicious verdict were recorded. The file has existed since June 2020 with over 36 000 submissions and no engine consensus on any threat family.
What To Do Now
Do not execute the sample. Verify the file against an official Adobe distribution channel or obtain a properly code-signed installer from Adobe's site. If the file is required for legacy purposes, run it only in an isolated environment with network monitoring.
The strongest scan facts behind the verdict, preserved with their exact names and counts.
0 of 74 antivirus engines flagged the file.
The hash has been submitted 36,935 times from 3,645 sources.
- Zero detections from 74 engines including 16 tier-1 clean reports
- Common_old prevalence (3645 sources, 36935 submissions)
- No malicious dropped children or contacted hosts
- Unverified code signature claiming Adobe Inc.
- Sandbox observed T1055 process injection
- Direct-IP contact without DNS resolution
Treat as untrusted; obtain a verified Adobe installer from official sources before any execution.
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Created or modified a system service, which can keep code running.
High concern: Changed an auto-start location that can make code run after sign-in or restart.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't run it unless you're certain it came from a source you trust.
Check where you got it — an email attachment or a random download link is a red flag.
If you're unsure, delete it. You can always re-download a clean copy from the official source.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 104.18.11.39
- a83f:8110:700:0:ec3f:1c0:100:0
- 104.18.10.39
- 23.59.190.193
- 192.168.0.66
- 13.107.4.50
- 20.80.129.13
- a83f:8110:2e74:6578:7424:7800:c01f:0
- 131.253.33.203
- 192.168.0.61
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e60f74d0bf521415
- http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D
- http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAbyTZ9NsHvX7K0Gf17ibCk%3D
- http://crl.verisign.com/pca3.crl
- C:\Users\<USER>\AppData\Local\Temp\CreativeCloud\ACC\AdobeDownload\HDInstaller.log
- C:\Users\<USER>\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
- C:\Users\user\AppData\Local\Temp\CreativeCloud\ACC\AdobeDownload\HDInstaller.log
- C:\Users\user\AppData\Local\Temp
- C:\Users\user\AppData\Local\Temp\CreativeCloud
- C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
- C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER15B5.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER177A.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1827.tmp.txt
- HDInstaller.log
- Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
- Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
- Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
- Global\C::Users:admin:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 0368bfe643c2d2005311…5f289fNever scannednever seen before
- f35238da1e9a739caf6d…928e9bNever scannednever seen before
- a53a8237b1c0e9b2ec42…cf94dcNever scannednever seen before
- 4de77d2df7d285e4a2ba…39264eNever scannednever seen before
- 451b2bd009523777a1e4…a6e838Never scannednever seen before
- 99cb2a31fffc1b6cd7d7…09dd3dNever scannednever seen before
- cbd79315982389cf75ab…5e89f8Never scannednever seen before
- eb3a677248868d530a29…930c98Never scannednever seen before
- 68095e77b9a1a8ae411a…55315fNever scannednever seen before
- 13c0e1644f4615865c6b…345981Never scannednever seen before
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESample contacted 15 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence104.18.11.39 · a83f:8110:700:0:ec3f:1c0:100:0 · 104.18.10.39
0 detections across 74 engines
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- Adobe Installer
- Size
- 7.25 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- b9a187b59c758ead0022e50bbaae4133d2e37b769a054249afc0b6aa2e26774d
- MD5
- de70f0deed893bba56ccb78eafd59606
- SHA-1
- f351b0c2996a3573d36deab9b6b3961876189f71
- PE imphash
- e133890b059ac017fed069a78f415ebe
- First seen (VT)
- Jun 30, 2020, 10:14 AM UTC
- Last analysis (VT)
- Jul 20, 2026, 10:31 PM UTC
- First scan (MalwareTips)
- Jul 22, 2026, 10:58 AM UTC
- Last scan (MalwareTips)
- Jul 22, 2026, 1:59 PM UTC
- Code signer
- Adobe Inc.invalid
- Community reputation
- +15trusted
Safety FAQ
Common questions about Adobe Installer, answered from the scan data above.
- Adobe Installer is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
- Adobe Installer is a software installer, about 7.3 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- None — all 74 antivirus engines we queried report Adobe Installer as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove Adobe Installer: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Adobe Installer file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- Adobe Installer claims a signer of Adobe Inc., but the signature is not verified — an unverified or broken signature can be forged, so it should not be trusted as proof of who made the file.
- The SHA-256 hash of Adobe Installer is b9a187b59c758ead0022e50bbaae4133d2e37b769a054249afc0b6aa2e26774d, and its MD5 is de70f0deed893bba56ccb78eafd59606. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 22, 2026. Because a file's hash never changes, the identity of Adobe Installer is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.