ProfileVisitor.exe

ProfileVisitor

The executable ProfileVisitor.exe has been detected as malware by 21 anti-virus scanners. The file has been seen being downloaded from d2f36wdth8exn9.cloudfront.net.
Product:
ProfileVisitor

Version:
1.0.0.0

MD5:
d5d64fa8de10f78e673b310259ac76ae

SHA-1:
08b65f121bc560f2b801aad0116a5f503c3a3b9a

SHA-256:
455790cf1cbe368bee3367ed752276a84b4c5db56ede2c0c5e5245a273bfdb49

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
4/30/2024 8:14:12 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Facbot.A
7.11.96.122

avast!
Win32:Trojan-gen
2014.9-141003

AVG
Generic33
2015.0.3333

Bitdefender
Trojan.GenericKDV.1057800
1.0.20.1380

Comodo Security
UnclassifiedMalware
16754

Dr.Web
Trojan.MulDrop4.49432
9.0.1.0276

Emsisoft Anti-Malware
Trojan.GenericKDV.1057800
8.14.10.03.09

ESET NOD32
JS/Chromex.FBook (variant)
8.8680

F-Secure
Trojan.GenericKDV.1057800
11.2014-03-10_6

G Data
Trojan.GenericKDV.1057800
14.10.22

IKARUS anti.virus
Trojan.Win32.Facbot
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9261

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.3158

McAfee
Artemis!D5D64FA8DE10
5600.6989

Microsoft Security Essentials
Trojan:Win32/Facbot.A
1.163.1557.0

Norman
Troj_Generic.MDVYH
11.20141003

Panda Antivirus
Trj/CI.A
14.10.03.09

Quick Heal
Trojan.Facbot
10.14.12.00

Trend Micro House Call
TROJ_GEN.F0C2C0KH213
7.2.276

Trend Micro
TROJ_GEN.F0C2C0KH213
10.465.03

VIPRE Antivirus
Trojan.Win32.Generic
20440

File size:
366.5 KB (375,296 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
ProfileVisitor.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\profilevisitor.exe

File PE Metadata
Compilation timestamp:
6/10/2013 2:14:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:aTzA86SZvstVcou1lYfyYrRuGqBrstVcou1lYfyYrRuGqB3:kA86W1ou1lYfC5ou1lYfC

Entry address:
0x5D16E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5123

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
364.5 KB (373,248 bytes)

The file ProfileVisitor.exe has been seen being distributed by the following URL.

Remove ProfileVisitor.exe - Powered by Reason Core Security