photo_016.jpeg-www.facebook.com.exe

WifiInfoView

NirSoft

The executable photo_016.jpeg-www.facebook.com.exe has been detected as malware by 5 anti-virus scanners. The file has been seen being downloaded from www.bustler.net and multiple other hosts.
Publisher:
NirSoft

Product:
WifiInfoView

Version:
1.26

MD5:
eaf59b9e9f61f9e32c80d6ef31dd2287

SHA-1:
fed7e02dda967a9be586fedcb9345ffc48ef750b

SHA-256:
76e2d4ce7ae05ef46dbc8b9ad6740737069f0b2c2a3d0bd329a6e30c8824ba27

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/25/2024 1:08:31 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/TorSolar.A.28
7.11.131.26

Bkav FE
HW32.CDB
1.3.0.4924

ESET NOD32
Win32/Injector.AXNZ (variant)
8.9413

Fortinet FortiGate
W32/Injector.AVRA!tr
2/12/2014

IKARUS anti.virus
Trojan-Ransom.Win32.Foreign
t3scan.2.2.29

File size:
191 KB (195,584 bytes)

Product version:
1.26

Copyright:
Copyright © 2012 - 2013 Nir Sofer

Original file name:
WifiInfoView.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\photo_016.jpeg-www.facebook.com.exe

File PE Metadata
Compilation timestamp:
2/11/2014 10:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:cTdw3hxbMBXo9KC7yjXmqFkhPPm8I9sZlrVUYV9Q7djuT/5r3fNa7VJLRf1ii:bxoBXgKCBhPPtrZrh7la7VJNYi

Entry address:
0x2C21

Entry point:
E8, 09, 62, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, 55, 8B, EC, 53, 56, 57, 55, 6A, 00, 6A, 00, 68, 48, 2C, 40, 00, FF, 75, 08, E8, 7C, 7F, 00, 00, 5D, 5F, 5E, 5B, 8B, E5, 5D, C3, 8B, 4C, 24, 04, F7, 41, 04, 06, 00, 00, 00, B8, 01, 00, 00, 00, 74, 32, 8B, 44, 24, 14, 8B, 48, FC, 33, C8, E8, 85, FD, FF, FF, 55, 8B, 68, 10, 8B, 50, 28, 52, 8B, 50, 24, 52, E8, 14, 00, 00, 00, 83, C4, 08, 5D, 8B, 44, 24, 08, 8B, 54, 24, 10, 89, 02, B8, 03, 00, 00, 00, C3, 53, 56, 57, 8B, 44, 24, 10, 55, 50, 6A, FE, 68...
 
[+]

Entropy:
7.5905

Code size:
40 KB (40,960 bytes)

The file photo_016.jpeg-www.facebook.com.exe has been seen being distributed by the following 3 URLs.

http://www.bustler.net/?u4wkiu6oah019sqw=8d2777d1c27

Remove photo_016.jpeg-www.facebook.com.exe - Powered by Reason Core Security