angrybirds.exe

Rovio Mobile Ltd.

The executable angrybirds.exe has been detected as malware by 4 anti-virus scanners.
Publisher:
Rovio Mobile Ltd.  (signed and verified)

MD5:
5779cf593f7335a41655865d8340ef75

SHA-1:
cbdcc6c6a513d233cb31bfbe6f24755fdc176723

SHA-256:
0511d2f7390dc122413f553aaaced6b8ad062c0f3d21fca80696314bfccae33f

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/18/2024 12:56:12 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Patched.Ren.Gen
8.3.2.4

avast!
Win32:Evo-gen [Susp]
151004-0

K7 AntiVirus
Riskware
13.212.17997

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1077

File size:
1.2 MB (1,232,128 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
TC TrustCenter GmbH

Valid from:
4/19/2010 4:39:23 PM

Valid to:
4/19/2011 4:39:23 PM

Subject:
CN=Rovio Mobile Ltd., OU=Symbian Signed PublisherID, OU=Sales, O=Rovio Mobile Ltd., L=Helsinki, S=Uusimaa, C=FI

Issuer:
CN=TC TrustCenter Class 2 L1 CA XII, OU=TC TrustCenter Class 2 L1 CA, O=TC TrustCenter GmbH, C=DE

Serial number:
00CDFA0001000276D9EDCA7348AC93

File PE Metadata
Compilation timestamp:
1/4/2011 9:32:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:o0r7wzhmqrBYEvUjc8kciUptj36PB1k3ymjSvQp0j4rmNnLo6A0TRoUkZzondY3:oc7wVmUAKfk8amDA0TRaZzondo

Entry address:
0xB4884

Entry point:
E8, BA, 04, 00, 00, E9, 63, FD, FF, FF, CC, CC, FF, 25, C8, 62, 4D, 00, FF, 25, C4, 62, 4D, 00, FF, 25, C0, 62, 4D, 00, FF, 25, BC, 62, 4D, 00, FF, 25, B8, 62, 4D, 00, FF, 25, B4, 62, 4D, 00, FF, 25, B0, 62, 4D, 00, FF, 25, B0, 60, 4D, 00, 83, 3D, E4, 93, 51, 00, 00, 74, 2D, 55, 8B, EC, 83, EC, 08, 83, E4, F8, DD, 1C, 24, F2, 0F, 2C, 04, 24, C9, C3, 83, 3D, E4, 93, 51, 00, 00, 74, 11, 83, EC, 04, D9, 3C, 24, 58, 66, 83, E0, 7F, 66, 83, F8, 7F, 74, D3, 55, 8B, EC, 83, EC, 20, 83, E4, F0, D9, C0, D9, 54, 24...
 
[+]

Entropy:
6.8867

Code size:
851.5 KB (871,936 bytes)

Remove angrybirds.exe - Powered by Reason Core Security