facebook-pro.exe

The executable facebook-pro.exe has been detected as malware by 9 anti-virus scanners. The file has been seen being downloaded from facebook-pro-app.en.softonic.com.
MD5:
1c9a0f2a3659cc4f52ef7ec44d2416d1

SHA-1:
2e866c3b8f95e419d053eb918612332a8c82431a

SHA-256:
45820df70f4063df1c28c14dca2cddd44119494a8b937b782a36321bfe19da45

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
2/26/2025 4:17:25 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160327-1

AVG
Win32/Virut
2015.0.4355

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Worm.Generic.377772
11.5.0.6191

ESET NOD32
Win32/Virut.NBP virus
8.0.319.0

F-Prot
W32/Virut.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Gnamer
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.984.0

File size:
620.5 KB (635,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\facebook-pro.exe

File PE Metadata
Compilation timestamp:
4/30/1997 8:01:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:0rMIztyCK5x8CBmn+RrNbEyWYa0Ie1vUxjVau9:mZyCA8CBmn+RrNj9ay5Gl9

Entry address:
0x9F000

Entry point:
89, D2, 83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 80, E9, 00, 60, 87, EA, 83, EC, DC, E8, 1E, 68, 00, 00, 80, F2, B5, 4B, 86, F5, 66, 4B, 75, FC, FE, C4, 86, E0, FF, 73, 3C, E9, BF, 68, 00, 00, B7, DF, 77, F2, D4, C8, 9C, F8, ED, AB, A8, D7, B3, 8D, 5D, 8A, DF, 4D, 95, 34, 8E, 34, CC, B9, 04, CB, 59, 7A, EE, 1E, B6, 3C, 5A, 87, 64, 82, 5C, BA, 09, B8, F6, 8B, F7, 4E, 21, 76, 81, 2A, 0E, DD, 5C, EA, 36, 72, DB, 07, AA, BB, B8, 84, 30, E1, 7E, 5B, 9B, FC, 92, 09, 05, CF, BE, 16, 9E, 3B, 9C, FA, E7, 25, 65, 95...
 
[+]

Entropy:
6.2226

Code size:
451 KB (461,824 bytes)

The file facebook-pro.exe has been seen being distributed by the following URL.

Remove facebook-pro.exe - Powered by Reason Core Security