photo_016-www.facebook.com.exe

Raize Software, Inc.

The executable photo_016-www.facebook.com.exe, “CodeSite Tools 5.0” has been detected as malware by 38 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from tuvaustriahellas.gr and multiple other hosts.
Publisher:
Raize Software, Inc.

Description:
CodeSite Tools 5.0

Version:
5.0

MD5:
e918ae5279ccbb47d9d2fa0f92fbf2ee

SHA-1:
7d54d7a937cf0ac899e937834d913ebd0027d8b0

SHA-256:
1f11b896cc641db605d70186be468a148a64ea233a21d353e7483239e71e1516

Scanner detections:
38 / 68

Status:
Malware

Analysis date:
4/26/2024 4:55:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.35738
569

Agnitum Outpost
Trojan.DR.Dapato
7.1.1

AhnLab V3 Security
Dropper/Win32.Dapato
2014.09.12

Avira AntiVirus
TR/Napolar.A.10
7.11.171.176

avast!
Win32:Napolar-E [Cryp]
2014.9-150715

AVG
Dropper.Generic8
2016.0.3047

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.15715

Bitdefender
Gen:Variant.Symmi.35738
1.0.20.980

Bkav FE
HW32.Paked
1.3.0.4959

Comodo Security
Backdoor.Win32.Agent.CXI4
19481

Dr.Web
Trojan.PWS.Panda.4784
9.0.1.0196

Emsisoft Anti-Malware
Gen:Variant.Symmi.35738
8.15.07.15.05

ESET NOD32
Win32/Agent.VAE
9.10402

Fortinet FortiGate
W32/Dapato.DAQX!tr
7/15/2015

F-Prot
W32/Dapato.E
v6.4.7.1.166

F-Secure
Gen:Variant.Symmi.35738
11.2015-15-07_4

G Data
Gen:Variant.Symmi.35738
15.7.24

IKARUS anti.virus
Trojan-Dropper.Win32.Dapato
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13345

Kaspersky
Trojan-Dropper.Win32.Dapato
14.0.0.1731

Malwarebytes
Trojan.Agent.FICO
v2015.07.15.05

McAfee
W32/Napsolar-FHO!E918AE5279CC
5600.6703

Microsoft Security Essentials
Trojan:Win32/Napolar.A
1.10904

MicroWorld eScan
Gen:Variant.Symmi.35738
16.0.0.588

NANO AntiVirus
Trojan.Win32.Dapato.ccsous
0.28.2.61942

Norman
Suspicious_Gen4.ETTRO
11.20150715

Panda Antivirus
Trj/Dtcontx.G
15.07.15.05

Qihoo 360 Security
HEUR/Malware.QVM05.Gen
1.0.0.1015

Quick Heal
TrojanDropper.Dapato.ra
7.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.7.17.0

Rising Antivirus
PE:Trojan.Win32.Generic.15A55663!363157091
23.00.65.15713

Sophos
Troj/Napolar-A
4.98

SUPERAntiSpyware
Heur.Agent/Gen-GalPic[i]
9752

Trend Micro House Call
TROJ_NAPOLAR.NIL
7.2.196

Vba32 AntiVirus
BScope.Malware-Cryptor.Napolar.2683
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Napolar.a
33018

ViRobot
Dropper.Dapato.116224
2011.4.7.4223

Zillya! Antivirus
Trojan.Fareit.Win32.2070
2.0.0.1917

File size:
113.5 KB (116,224 bytes)

Copyright:
© 1998-2011, Raize Software, Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\photo_016-www.facebook.com.exe

File PE Metadata
Compilation timestamp:
8/23/2013 10:39:40 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:Hg9LXJ9aap4HNz7zpqOfv5VCdXx122xlbARk0SE:A9jJ9t4HJ7VP4nPxlbAk0

Entry address:
0x50B4

Entry point:
55, 8B, EC, 83, C4, F0, B8, DC, 46, 40, 00, E8, 28, EB, FF, FF, E8, 93, F4, FF, FF, E8, 82, E5, FF, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
15.5 KB (15,872 bytes)

The file photo_016-www.facebook.com.exe has been seen being distributed by the following 3 URLs.

http://tuvaustriahellas.gr/?bb45dk=b791a983

Remove photo_016-www.facebook.com.exe - Powered by Reason Core Security