facebook videos.flv.exe

Sunny Player

The executable facebook videos.flv.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from siparisodemesi.com.
Publisher:
Microsoft*  (Invalid match)

Product:
Sunny Player

Version:
1.0.0.0

MD5:
faccd651f993327f3d7a8a9a76ad0b9d

SHA-1:
c44fe0dfefbfa1b1e7d2a9cdfda1331f59d628cf

SHA-256:
3bc7381f22e273c6979a8ce49444f4d1f3924d881d2eb4f01f323b8426f2a34e

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
11/28/2024 12:46:51 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.114132
509

Avira AntiVirus
TR/Zusy.36352.2
7.11.196.252

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150914

AVG
MSIL5
2016.0.2987

Bitdefender
Gen:Variant.Zusy.114132
1.0.20.1285

Dr.Web
Trojan.DownLoader11.40897
9.0.1.0257

Emsisoft Anti-Malware
Gen:Variant.Zusy.114132
8.15.09.14.06

ESET NOD32
MSIL/ExtenBro.AA (variant)
9.10907

Fortinet FortiGate
MSIL/ExtenBro.Y!tr
9/14/2015

F-Secure
Trojan:W32/Kilim.AG
11.2015-14-09_2

G Data
Gen:Variant.Zusy.114132
15.9.24

IKARUS anti.virus
Trojan.MSIL.ExtenBro
t3scan.1.8.5.0

Kaspersky
Trojan.MSIL.Agent
14.0.0.1429

Malwarebytes
Trojan.MSIL
v2015.09.14.06

McAfee
Artemis!FACCD651F993
5600.6643

Microsoft Security Essentials
Trojan:MSIL/Kilim.F
1.11302

MicroWorld eScan
Gen:Variant.Zusy.114132
16.0.0.771

Norman
Troj_Generic.XCXEY
11.20150914

Quick Heal
Trojan.MSI.r4
9.15.14.00

Sophos
Mal/MSIL-LX
4.98

Trend Micro House Call
TROJ_GEN.R00UC0EL114
7.2.257

Trend Micro
TROJ_GEN.R00UC0EL114
10.465.14

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
35946

Zillya! Antivirus
Trojan.Agent.Win32.495543
2.0.0.2011

File size:
35.5 KB (36,352 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2014

Original file name:
Sunny Player.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\facebook videos.flv.exe

File PE Metadata
Compilation timestamp:
10/30/2014 1:43:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:gPR//KROvqF+q71rPhnp0Y9VyTCP4MqnGF:gPR//KROvxq71rPN9MMqG

Entry address:
0x60CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.5 KB (16,896 bytes)

The file facebook videos.flv.exe has been seen being distributed by the following URL.

Remove facebook videos.flv.exe - Powered by Reason Core Security