fb hack v1.1.2.exe

E/oit%dbbAds

z5lhq4cbawdp

The executable fb hack v1.1.2.exe has been detected as malware by 11 anti-virus scanners. The file has been seen being downloaded from dc209.gulfup.com.
Publisher:
z5lhq4cbawdp

Product:
E/oit%dbbAds

Description:
z5lhq4cbawdp

Version:
4.1.5.?0

MD5:
1d811b0533967d89502c8ad40d9d7dfc

SHA-1:
10913ac0aef33711d6ce4c37a4abb0e8376b3972

SHA-256:
f9434dbcef289031874c4a42196f365c8ca6af5d3e807d80ea9bf30058c48784

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
5/10/2024 2:21:00 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.347104
884

Avira AntiVirus
TR/Crypt.CFI.Gen
7.11.169.150

avast!
MSIL:Agent-BZJ [Trj]
2014.9-140903

Bitdefender
Gen:Variant.Kazy.347104
1.0.20.1230

Emsisoft Anti-Malware
Gen:Variant.Kazy.347104
8.14.09.03.04

ESET NOD32
MSIL/Injector.DBQ (variant)
8.10325

F-Secure
Gen:Variant.Kazy.347104
11.2014-03-09_4

G Data
Gen:Variant.Kazy.347104
14.9.24

Malwarebytes
Trojan.MSIL
v2014.09.03.04

McAfee
Trojan-FDWX!1D811B053396
5600.7018

MicroWorld eScan
Gen:Variant.Kazy.347104
15.0.0.738

File size:
2.7 MB (2,876,928 bytes)

Product version:
4.1.5.?0

Copyright:
z5lhq4cbawdp

Trademarks:
E/oit%dbbAds

Original file name:
LoOoL.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\fb hack v1.1.2.exe

File PE Metadata
Compilation timestamp:
8/27/2014 2:37:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:IsXgfmGANxQ4LAPwurQ+cZ7tIjlz60NnkVAVal4Mx9EEFzZIYZuJa62SLXsXIr9t:IUNxf+g7tWPkVMMnPFtwV2SLXdpyJEn6

Entry address:
0x2BF0DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5214

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.7 MB (2,871,808 bytes)

The file fb hack v1.1.2.exe has been seen being distributed by the following URL.

Remove fb hack v1.1.2.exe - Powered by Reason Core Security