app.exe

The executable app.exe has been detected as malware by 27 anti-virus scanners.
MD5:
48d35dfd81593ea961e50f6fb4fa2580

SHA-1:
5921c1faf05f88d79f32919521af9bb237c554b4

SHA-256:
2ca0a3d8a09383eac0df255a46be8aa3f400cd1d2dc75abd699ffe1c46a01916

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/30/2024 5:33:01 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Mabezat
5.0.

Avira AntiVirus
Worm/Mabezat.b
7.9.1.53

Emsisoft A-Squared
Worm.Win32.Mabezat!IK
4.5.0.41

avast!
Win32:Mabezat-AM
2014.9-170313

AVG
Worm/Mabezat.A
2018.0.2440

Bitdefender
Worm.Generic.65976
1.0.20.360

Clam AntiVirus
W32.Mabezat-2
0.98/171

Comodo Security
Worm.Win32.Mabezat.b
2849

Dr.Web
Win32.HLLW.Tazebama
9.0.1.072

ESET NOD32
Win32/Mabezat
11.4576

Fortinet FortiGate
W32/Mabezat.B
3/13/2017

F-Prot
W32/Mabezat.A
v6.4.5.1.85

F-Secure
Worm.Generic.65976
11.2017-13-03_2

G Data
Worm.Generic.65976
17.3.19

IKARUS anti.virus
Worm.Win32.Mabezat
t3scan.1.1.74.0

K7 AntiVirus
Virus.Win32.Mabezat.b-3
13.7.10.889

Kaspersky
Worm.Win32.Mabezat
14.0.0.-1305

McAfee
W32/Mabezat
5600.6096

Microsoft Security Essentials
Virus:Win32/Mabezat.B
1.163.1557.0

Norman
Mabezat.B
11.20170313

Panda Antivirus
W32/Mabezat.C.worm
17.03.13.11

Quick Heal
W32.Mabezat.Dr
3.17.10.00

Rising Antivirus
Worm.Win32.Autorun.gcy
23.00.65.17311

Sophos
W32/Mabezat-B
4.47

Trend Micro
PE_MABEZAT.B-O
10.465.13

Vba32 AntiVirus
Worm.Win32.Mabezat.b
3.12.10.11

ViRobot
Worm.Win32.Mabezat.154751
2009.11.5.2023

File size:
151.1 KB (154,771 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\adobe\acrobat reader dc\reader\webresources\resource0\static\js\app\app.exe

File PE Metadata
Compilation timestamp:
10/29/2007 9:17:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1000

Entry point:
53, 83, EC, 44, B8, 23, 10, 40, 00, B9, 00, 00, 00, 00, 8A, 18, 80, C3, 07, 88, 18, 83, C0, 01, 83, C1, 01, 81, F9, 37, D1, 00, 00, 75, EB, B1, F9, F9, 3A, F9, B2, F9, F9, F9, F9, 83, 11, 79, BC, 75, 81, 11, 7C, BA, FA, 7C, B9, FA, 7A, F2, F8, 20, F9, F9, 6E, E4, B1, F9, 09, 39, F9, B4, BC, BC, BC, BC, 82, 11, B1, CE, D3, 39, F9, 7C, B9, F9, 7C, BD, 3D, F8, C9, BC, 54, BC, E1, FE, F9, F9, F9, E2, 03, F9, F9, F9, B2, D1, 20, 3A, F9, E2, 64, AE, F9, F9, 61, 77, 09, 39, F9, E1, 28, C2, F9, F9, 52, BC, B2, D1...
 
[+]

Entropy:
7.0112

Code size:
52.5 KB (53,760 bytes)

Remove app.exe - Powered by Reason Core Security