Hack Facebook.exe

Hack Account Facebook - Brute Force

The application Hack Facebook.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc625.4shared.com.
Publisher:
Hack Account Facebook - Brute Force

Product:
Hack Account Facebook - Brute Force

Version:
1.0.0.0

MD5:
59495202c273ae3c9ed4e706c2cb201e

SHA-1:
600aff948713bcf9f2503be5fc80beee19947947

SHA-256:
4053896a9d66eeb9b3a79e7cfe6e96e1b83e109bc25f58c4c1f20d658ecfae71

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
The NirSoft utility is not necessarily bad (we don't beleive so), but some scan engines worry that its functionality can be used in a malicious manner.

Analysis date:
4/18/2024 6:36:48 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.NirSoft.IEPassView.F
5813612

Clam AntiVirus
Win.Trojan.Mailpassview-39
0.98/21301

Dr.Web
infected with Trojan.PWS.Usbthief
9.0.1.05190

ESET NOD32
Win32/AdapterWatch.A potentially unsafe application
7.0.302.0

F-Prot
File is encrypted
4.6.5.141

F-Secure
Application.Heur.hmKfb8qWL1kO
5.15.21

Kaspersky
not-a-virus:PSWTool.Win32.NetPass
15.0.0.562

McAfee
Program.Artemis!CB271441FA19
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.4224.0

Sophos
PUA 'Adapter Watch'
5.23

VIPRE Antivirus
Threat.4150696
46444

File size:
5.7 MB (5,942,723 bytes)

Product version:
1.0.0.0

Copyright:
Hack Account Facebook - Brute Force

Trademarks:
Hack Account Facebook - Brute Force

Original file name:
Hack Facebook .exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\hack facebook.exe

File PE Metadata
Compilation timestamp:
5/18/2010 1:39:19 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:qLkqqVW5/pM9xBCyG9ARjFtnYppsHdqKq81rRAIKC05ot9ybQlJbsySBRMXYM:qLkqVRpkBCyG96JYpeHdh1tAQ05otuQD

Entry address:
0x2CB3C

Entry point:
E8, 15, C6, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 10, 06, 45, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 10, 06, 45, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Code size:
253.5 KB (259,584 bytes)

The file Hack Facebook.exe has been seen being distributed by the following URL.

Remove Hack Facebook.exe - Powered by Reason Core Security