foxitreader621.0618.exe

Foxit Reader

The executable foxitreader621.0618.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from foxit.joydownload.com.
Product:
Foxit Reader

Version:
1.0.0.0

MD5:
49355b515d52319c036d8211a6b10ed4

SHA-1:
74ccf012bd17d8090d8c97f720a8658c73c18065

SHA-256:
e50f5f2a69c1dca4fb76e266e8dd4fbf98bc9877678d7067c3fbc43643bd2cfd

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 9:58:59 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160216-0

AVG
Win32/Sality
2015.0.4530

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5735

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Trojan.Artemis!4A21E1E9064A
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.7574.0

File size:
576.7 KB (590,584 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
5/20/2013 6:52:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:uQzDEdm9xf1b3QVo/si4BC8cJLm4cU9FT644Dp3p3tcs:/zw03+W/f4M8cJi4t9MXN3

Entry address:
0x331F

Entry point:
38, DC, 0F, BE, FD, 0F, AF, C0, 80, F9, 99, FF, CB, F3, 43, 20, FD, 31, D5, 0F, AF, C9, 3B, F0, F2, 69, FF, 3E, FD, 48, 30, 81, D7, E2, 6D, 56, 5D, 8D, 15, 81, 6A, 33, 41, 89, F1, 0F, BF, FD, 43, 0C, A3, E8, 60, 00, 00, 00, 0F, BE, EA, 8A, C3, 70, 05, F6, C4, EC, 88, F2, 81, FD, 8C, 76, 00, 00, 78, 06, 0F, AF, C9, F6, C4, BE, F6, C1, 38, 19, D5, 0F, B6, E9, C6, C4, FD, BA, 69, 33, 00, 00, 0F, B7, EB, 84, F7, 81, F2, 38, 9D, 00, 00, 8A, E0, 81, EA, 47, 01, 00, 00, C6, C4, 84, C6, C0, 47, 8D, 1A, 40, 81, C3...
 
[+]

Entropy:
7.8914  (probably packed)

Code size:
24 KB (24,576 bytes)

The file foxitreader621.0618.exe has been seen being distributed by the following URL.

Remove foxitreader621.0618.exe - Powered by Reason Core Security