fi-fi.exe

The executable fi-fi.exe has been detected as malware by 26 anti-virus scanners.
MD5:
4fe73c4d51a0e626761ec0dcb8dfd820

SHA-1:
86f90ffc200a7959e2ab1eabcfe329dfdf10f871

SHA-256:
9ac58255591c8f060a2e771c9cdcfd0541128d67fba4c97fd47d9e258bf4627e

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/30/2024 9:03:59 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Mabezat
5.0.

Avira AntiVirus
Worm/Mabezat.b
7.9.1.8

Emsisoft A-Squared
Worm.Win32.Mabezat!IK
4.5.0.24

avast!
Win32:Mabezat-AM
2014.9-170314

AVG
Worm/Mabezat.A
2018.0.2440

Bitdefender
Worm.Generic.65976
1.0.20.365

Clam AntiVirus
W32.Mabezat-2
0.98/171

Dr.Web
Win32.HLLW.Tazebama
9.0.1.073

ESET NOD32
Win32/Mabezat
11.4398

Fortinet FortiGate
W32/Mabezat.B
3/14/2017

F-Prot
W32/Mabezat.A
v6.4.5.1.85

F-Secure
Worm.Win32.Mabezat.b
11.2017-14-03_3

G Data
Worm.Generic.65976
17.3.19

IKARUS anti.virus
Worm.Win32.Mabezat
t3scan.1.1.72.0

K7 AntiVirus
Virus.Win32.Mabezat.b-3
13.7.10.836

Kaspersky
Worm.Win32.Mabezat
14.0.0.-1305

McAfee
W32/Mabezat
5600.6096

Microsoft Security Essentials
Virus:Win32/Mabezat.B
1.163.1557.0

Norman
Mabezat.B
11.20170314

Panda Antivirus
W32/Mabezat.C.worm
17.03.14.12

Quick Heal
W32.Mabezat.Dr
3.17.10.00

Rising Antivirus
Worm.Win32.Autorun.gcy
23.00.65.17312

Sophos
W32/Mabezat-B
4.45

Trend Micro
PE_MABEZAT.B-O
10.465.14

Vba32 AntiVirus
Worm.Win32.Mabezat.b
3.12.10.10

ViRobot
Worm.Win32.Mabezat.154751
2009.9.4.1919

File size:
151.4 KB (155,061 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\adobe\acrobat reader dc\reader\webresources\resource0\static\js\plugins\home\js\nls\fi-fi\fi-fi.exe

File PE Metadata
Compilation timestamp:
10/29/2007 9:17:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1000

Entry point:
53, 83, EC, 44, B8, 23, 10, 40, 00, B9, 00, 00, 00, 00, 8A, 18, 80, C3, 10, 88, 18, 83, C0, 01, 83, C1, 01, 81, F9, 37, D1, 00, 00, 75, EB, A8, F0, F0, 31, F0, A9, F0, F0, F0, F0, 7A, 08, 70, B3, 0E, 78, 08, 73, B1, F1, 73, B0, F1, 71, E9, EF, 17, F0, F0, 65, DB, A8, F0, 00, 30, F0, AB, B3, B3, B3, B3, 79, 08, A8, C5, CA, 30, F0, 73, B0, F0, 73, B4, 34, EF, C0, B3, 4B, B3, D8, F5, F0, F0, F0, D9, FA, F0, F0, F0, A9, C8, 17, 31, F0, D9, 5B, A5, F0, F0, 58, 6E, 00, 30, F0, D8, 1F, B9, F0, F0, 49, B3, A9, C8...
 
[+]

Entropy:
7.0495

Code size:
52.5 KB (53,760 bytes)

Remove fi-fi.exe - Powered by Reason Core Security