Facebook Hack v2.1.exe

Facebook Hack v2.1

The executable Facebook Hack v2.1.exe has been detected as malware by 19 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc186.2shared.com.
Product:
Facebook Hack v2.1

Version:
1.0.0.0

MD5:
de3a24fd9707d49424accd4b59555474

SHA-1:
823ca7013c84e3497356069a3d478c9643bd1a20

SHA-256:
40e737f1d5dbe225d089140b99684795600ab3d453c8541d7ede45a38eb663b1

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
11/27/2024 5:04:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.MSIL.Krypt.85
612

Agnitum Outpost
Trojan.Krypt
7.1.1

Avira AntiVirus
TR/Spy.A.13579
3.6.1.96

Baidu Antivirus
Trojan.MSIL.Facebook
4.0.3.1562

Bitdefender
Gen:Heur.MSIL.Krypt.85
1.0.20.765

Clam AntiVirus
Win.Trojan.Agent-709078
0.98/21511

Emsisoft Anti-Malware
Gen:Heur.MSIL.Krypt.85
8.15.06.02.12

ESET NOD32
MSIL/PSW.Facebook (variant)
9.11392

Fortinet FortiGate
MSIL/Agent.OFU!tr
6/2/2015

F-Secure
Gen:Heur.MSIL.Krypt.85
11.2015-02-06_3

G Data
Gen:Heur.MSIL.Krypt.85
15.6.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.9.0

K7 AntiVirus
Password-Stealer
13.202.15415

Malwarebytes
Trojan.Generic
v2015.06.02.12

McAfee
Artemis!DE3A24FD9707
5600.6746

MicroWorld eScan
Gen:Heur.MSIL.Krypt.85
16.0.0.459

Qihoo 360 Security
Win32/Trojan.fe7
1.0.0.1015

SUPERAntiSpyware
Trojan.Agent/Gen-Falofn[Cont]
9838

VIPRE Antivirus
Trojan.Win32.Generic
38850

File size:
1.2 MB (1,231,872 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2011

Original file name:
Facebook Hack v2.1.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\facebook hack v2.1.exe

File PE Metadata
Compilation timestamp:
6/22/2011 9:28:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:qcuu+h8g5t+zBTMao2doGltGuu+h8g5t+zBTMao2doGltEuu+h8g5t+zBTMao2dh:AlhyMao2doUtrlhyMao2doUtFlhyMaou

Entry address:
0xD35AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 67, 34, 02, 4E, 00, 00, 00, 00, 02, 00, 00, 00, A9, 00, 00, 00, 1C, 40, 0D, 00, 1C, 1A, 0D, 00, 52, 53, 44, 53, 9A, 7C, 54, A6, 57, 42, CC, 4F, 87, D7, B3, DD, C5, D7...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
837.5 KB (857,600 bytes)

The file Facebook Hack v2.1.exe has been seen being distributed by the following URL.

Remove Facebook Hack v2.1.exe - Powered by Reason Core Security