Firebird.exe

The executable Firebird.exe has been detected as malware by 23 anti-virus scanners. The file has been seen being downloaded from www.campeott.com.
Version:
1.0.0.0

MD5:
f1a2476c197b28763e516a26ce57c471

SHA-1:
b929f1e4a6ce449abf0903376636bab693e7c711

SHA-256:
7f9ce97cc472cb35359dc01a6663052b03bbc060896a4e2848a110fd5cdd38ff

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/19/2024 5:51:11 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Rogue.1203652
7.11.99.160

avast!
Win32:Malware-gen
2014.9-131126

AVG
PSW.Banker6
2014.0.3643

Bitdefender
Trojan.GenericKDV.1203652
1.0.20.1180

Comodo Security
Heur.Suspicious
16864

Dr.Web
Trojan.SMSSend.4473
9.0.1.0330

Emsisoft Anti-Malware
Trojan.GenericKDV.1203652
8.13.08.24.01

ESET NOD32
Win32/Spy.Banker.ZOX (variant)
7.8752

Fortinet FortiGate
W32/Banker.ZOX!tr.spy
11/26/2013

F-Secure
Trojan.GenericKDV.1203652
11.2013-26-11_3

G Data
Trojan.GenericKDV.1203652
13.8.22

IKARUS anti.virus
Trojan-PWS.Banker6
t3scan.2.0.127

K7 AntiVirus
Trojan
13.170.9438

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3768

Malwarebytes
Trojan.Banker
v2013.11.26.01

McAfee
Artemis!F1A2476C197B
5600.7176

MicroWorld eScan
Trojan.GenericKDV.1203652
14.0.0.708

NANO AntiVirus
Trojan.Win32.Banker.cbycfb
0.26.0.54268

Norman
Troj_Generic.OMPBW
11.20131126

Panda Antivirus
Trj/dtcontx.G
13.08.24.01

Reason Heuristics
Unnamed.Threat.41
14.3.1.0

Trend Micro House Call
TROJ_GEN.R0CBB01HR13
7.2.236

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
21090

File size:
4.7 MB (4,918,272 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\firebird.exe

File PE Metadata
Compilation timestamp:
8/21/2013 7:15:45 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:aOFkr5dOL29YZ2S285GGvzfHricuaAijR8Qpsn/I2C7iTx7kS/q0YhNfe//e:bWmT51vicuQR4I2C7AffsNfeXe

Entry address:
0x2BA164

Entry point:
55, 8B, EC, 83, C4, F0, B8, 14, DF, 6A, 00, E8, 0C, 48, D5, FF, 68, 2C, A2, 6B, 00, 68, 4C, A2, 6B, 00, E8, DD, 87, D5, FF, A3, 8C, D9, 6C, 00, 83, 3D, 8C, D9, 6C, 00, 00, 74, 0A, A1, 8C, D9, 6C, 00, E8, 71, FA, F9, FF, 68, 68, A2, 6B, 00, 68, 4C, A2, 6B, 00, E8, B6, 87, D5, FF, A3, 90, D9, 6C, 00, 83, 3D, 90, D9, 6C, 00, 00, 74, 0A, A1, 90, D9, 6C, 00, E8, 4A, FA, F9, FF, A1, 84, 73, 6C, 00, 8B, 00, E8, A2, 8B, EF, FF, A1, 84, 73, 6C, 00, 8B, 00, BA, 80, A2, 6B, 00, E8, 8D, 85, EF, FF, A1, 84, 73, 6C, 00...
 
[+]

Entropy:
7.0372

Developed / compiled with:
Microsoft Visual C++

Code size:
2.7 MB (2,853,376 bytes)

The file Firebird.exe has been seen being distributed by the following URL.

Remove Firebird.exe - Powered by Reason Core Security