flip.exe

The executable flip.exe has been detected as malware by 22 anti-virus scanners.
MD5:
b85506fc9f7d19a18dc5101d8bb15ba0

SHA-1:
4edd65fec6ceb6a6fe4f3b135477e84f13078e5e

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
4/26/2024 5:58:07 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Xema.variant
2010.11.29

avast!
Win32:Trojan-gen
2014.9-141126

AVG
Generic13
2015.0.3279

Bitdefender
Trojan.Generic.1678814
1.0.20.1650

Comodo Security
UnclassifiedMalware
6890

Emsisoft Anti-Malware
Trojan.Crypt!IK
8.14.11.26.07

ESET NOD32
Win32/Agent.HGIBYZU (variant)
8.5659

F-Prot
W32/MalwareS.ASTI
v6.4.6.2.117

F-Secure
Trojan.Generic.1678814
11.2014-26-11_4

G Data
Trojan.Generic.1678814
14.11.21

IKARUS anti.virus
Trojan.Crypt
t3scan.1.1.90.0

K7 AntiVirus
Trojan
13.63115

McAfee
Generic.dx!evl
5600.6935

Norman
W32/Smalltroj.IZXA
11.20141126

nProtect
Trojan/W32.Agent.67584.IG
10.11.29.01

Panda Antivirus
Trj/CI.A
14.11.26.07

Quick Heal
Trojan.Agent.ATV
11.14.11.00

Sophos
Mal/Generic-L
4.60

Trend Micro House Call
TROJ_Generic.DIT
7.2.330

Trend Micro
TROJ_Generic.DIT
10.465.26

Vba32 AntiVirus
Trojan.Win32.Genome.eqvc
3.12.14.2

VIPRE Antivirus
Trojan.Crypt.XPACK.Gen
7446

File size:
66 KB (67,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\flip.exe

File PE Metadata
Compilation timestamp:
9/2/2006 2:30:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.55

CTPH (ssdeep):
768:aSkDcv6P7q6LMqe8cM/U5F7MbgBH1ffB6vaem0AVPxJwxLpdcb5UzNjiqzR2kPlH:JeA6jrA3MsXxUvae2kPDNR9xyizo4

Entry address:
0x11F0

Entry point:
55, 89, E5, 83, EC, 08, 83, C4, F4, 6A, 02, A1, E0, 13, 41, 00, FF, D0, E8, 79, FF, FF, FF, C9, C3, 00, 00, 00, 00, 00, 00, 00, 55, 89, E5, 83, EC, 0C, 57, 56, 53, 8B, 5D, 08, 8B, 7D, 0C, 8B, 75, 10, 83, C4, F4, 6A, 20, E8, 94, 2B, 00, 00, 89, 18, 89, 70, 04, C7, 40, 08, 00, 00, 00, 00, C7, 40, 10, 00, 00, 00, 00, C7, 40, 0C, 00, 00, 00, 00, C7, 40, 14, 00, 00, 80, 3F, 89, 78, 18, C7, 40, 1C, 00, 00, 00, 00, 8D, 65, E8, 5B, 5E, 5F, C9, C3, 90, 55, 89, E5, 83, EC, 14, 53, 8B, 5D, 08, 83, C4, F4, FF, 73, 1C...
 
[+]

Packer / compiler:
Video-Lan-Client

Code size:
64.5 KB (66,048 bytes)

Remove flip.exe - Powered by Reason Core Security