filmora_setup_full1083.exe

Filmora

The executable filmora_setup_full1083.exe, “filmora_setup_full1083.exe” has been detected as malware by 12 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from download.wondershare.com.br.
Product:
Filmora

Description:
filmora_setup_full1083.exe

Version:
1,3,1,0

MD5:
195dd95200cfe3df8ee943ab339b289d

SHA-1:
c4afb2a2ac2cacc19e7746c064c715d94020bf0c

SHA-256:
f090cb7b8c6f1ee148c792481abbd973dc75b7783e21db7c9791dcb4f14d7d58

Scanner detections:
12 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/24/2024 1:34:27 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160118-1

AVG
Win32/Sality
2015.0.4477

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.4384.0

Norman
Win32.Sality.3
11.01.2016 17:30:26

Sophos
Virus 'Mal/Sality-D'
5.22

VIPRE Antivirus
Threat.4758034
46444

File size:
1.2 MB (1,266,160 bytes)

Product version:
6.7.0

Copyright:
Copyright 2015 Wondershare Corporation

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\filmora_setup_full1083.exe

File PE Metadata
Compilation timestamp:
11/25/2015 5:33:36 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:JzqhyVT39hDn6GPSbBAM1sWg2zUFvRUFv0/oUbYeK1:JzqhyVTbDvP4BA+g+UNRUNRU7K1

Entry address:
0x5161A

Entry point:
EB, 02, 84, FE, 48, C6, C0, 02, 8A, E1, 0F, C8, 81, F6, 72, 86, 00, 00, 20, F7, 68, AD, EB, 01, 00, 68, 69, E3, B9, 00, F6, DE, F6, C7, F4, E8, 00, 00, 00, 00, 8B, FF, 0F, CA, 39, EF, 85, D1, 73, 06, 69, C8, A5, F7, 9B, 65, F7, C1, B8, 45, 27, FC, 68, 00, 00, 00, 00, 8B, EB, 5A, 19, F1, F6, C0, 34, 81, F2, 43, 70, 10, 00, 38, DD, 4F, 92, 70, 02, 0F, CB, 2D, AF, B8, 0F, 00, 33, F0, EB, 09, 34, 81, 8A, E0, 0F, BF, D5, 0F, CF, 58, FE, C1, 0F, B7, F5, 0F, CF, BA, 42, 50, 00, 00, 81, EA, 04, 0D, 00, 00, 0F, 6E...
 
[+]

Packer / compiler:
FSG v1.10 (Microsoft Visual C++ 6.0 / 7.0)

Code size:
450.5 KB (461,312 bytes)

The file filmora_setup_full1083.exe has been seen being distributed by the following URL.

Remove filmora_setup_full1083.exe - Powered by Reason Core Security