fdff44d08d8401d465ace28c8201f410.pe

The file fdff44d08d8401d465ace28c8201f410.pe has been detected as malware by 42 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup.
MD5:
fdff44d08d8401d465ace28c8201f410

SHA-1:
d7d97ec3769f02b933ad264d3a500d2b26f1214b

SHA-256:
9c6f5f9d68f89c70defd7743834fcfe5d4ea2fa7f0a630605c5e7d2f0b66eb05

Scanner detections:
42 / 68

Status:
Malware

Analysis date:
4/19/2024 9:14:21 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8628969
658

Agnitum Outpost
Backdoor.Androm
7.1.1

AhnLab V3 Security
Downloader/Win32.Andromeda
2015.01.22

Avira AntiVirus
TR/Dropper.VB.Gen8
7.11.204.50

avast!
Win32:Trojan-gen
2014.9-150418

AVG
Downloader.Generic13
2016.0.3136

Baidu Antivirus
Trojan.Win32.Andromeda
4.0.3.15418

Bitdefender
Trojan.Generic.8628969
1.0.20.540

Bkav FE
W32.FamVT.Backdoor.VB.Trojan
1.3.0.6379

Clam AntiVirus
WIN.Downloader.Agent-395
0.98/18155

Comodo Security
TrojWare.Win32.TrojanDownloader.Andromeda.CD
20801

Dr.Web
Trojan.Siggen4.20010
9.0.1.0108

Emsisoft Anti-Malware
Trojan.Generic.8628969
8.15.04.18.09

ESET NOD32
Win32/Injector.WXP (variant)
9.11054

Fortinet FortiGate
W32/Injector.WXP!tr
4/18/2015

F-Prot
W32/VBcrypt.AM.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.8628969
11.2015-18-04_7

G Data
Trojan.Generic.8628969
15.4.24

IKARUS anti.virus
Trojan-Downloader.Win32.Andromeda
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.197.15038

Kaspersky
Backdoor.Win32.Androm
14.0.0.2173

Malwarebytes
Trojan.Andromeda
v2015.04.18.09

McAfee
W32/Worm-FDU!FDFF44D08D84
5600.6792

Microsoft Security Essentials
Worm:Win32/Gamarue
1.11302

MicroWorld eScan
Trojan.Generic.8628969
16.0.0.324

NANO AntiVirus
Trojan.Win32.Androm.dmhzjm
0.30.0.64812

Norman
Andromeda.UQ
11.20150418

nProtect
Trojan/W32.Agent.311296.UI
15.02.17.01

Panda Antivirus
Trj/Genetic.gen
15.04.18.09

Qihoo 360 Security
Win32/Worm.0c4
1.0.0.1015

Quick Heal
Worm.Gamarue.A3
4.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.13231B66!321067878
23.00.65.15416

Sophos
Troj/MDrop-FRP
4.98

SUPERAntiSpyware
Worm.Gamarue
9928

Total Defense
Win32/Gamarue.OGEbSaD
37.0.11397

Trend Micro House Call
TSPY_DOWNLOADER_BK08494B.TOMC
7.2.108

Trend Micro
TSPY_DOWNLOADER_BK08494B.TOMC
10.465.18

Vba32 AntiVirus
TrojanDownloader.Andromeda
3.12.26.3

VIPRE Antivirus
Worm.Win32.Vobfus.mc
36870

ViRobot
Trojan.Win32.Downloader.311296.T[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.Androm.Win32.11370
2.0.0.2076

File size:
304 KB (311,296 bytes)

Common path:
C:\users\{user}\downloads\fdff44d08d8401d465ace28c8201f410.pe

File PE Metadata
Compilation timestamp:
9/19/2012 4:20:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:ZIDNcIFN3tw4QfwmAOMe6UJbVM/vkA9OQzY6eCFs5Juh2v19hlDcfbEdp7uxEo+i:qJigOTJXYOaFs5Juh819hqkuGh2LeyI

Entry address:
0x109C

Entry point:
68, FC, 10, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 3C, DE, FF, 55, B5, AE, F8, 48, 83, 2E, 1F, B1, B2, D6, C3, 03, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 30, 3A, 46, 69, 72, 65, 66, 65, 6C, 6C, 65, 72, 00, 31, 00, 00, 00, 00, 07, 00, 00, 00, 50, 36, 40, 00, 07, 00, 00, 00, 08, 36, 40, 00, 07, 00, 00, 00, C4, 35, 40, 00, 56, 42, 35, 21, 36, 26, 2A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 7E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.4333

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
292 KB (299,008 bytes)

Remove fdff44d08d8401d465ace28c8201f410.pe - Powered by Reason Core Security