facemoods.exe

The application facemoods.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from i.facemoods.com.
MD5:
dd2aa6d5f31c7e02b929c39b0128f7e4

SHA-1:
ac7d40ae5aaee7df925a64f2d4d4d259e6a018cd

SHA-256:
e64994384bc145e624279b837ab107e570b5aeaa47fe0d52ff9ac5fc641c7dc7

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 12:31:28 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.189.82

AVG
Generic
2016.0.2980

Bkav FE
W32.HfsAutoA
1.3.0.6267

Comodo Security
UnclassifiedMalware
20217

Dr.Web
Adware.InstallCore.59
9.0.1.0264

ESET NOD32
Win32/InstallCore.AL (variant)
9.10794

Fortinet FortiGate
Riskware/InstallCore
9/21/2015

Malwarebytes
PUP.Funmoods
v2015.09.21.06

McAfee
Artemis!DD2AA6D5F31C
5600.6636

NANO AntiVirus
Riskware.Win32.InstallCore.debtzv
0.28.6.63726

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15919

Sophos
Install Core Installer
4.98

File size:
1.1 MB (1,135,832 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\facemoods.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:KY04GXqrXoAvmCp7X+KD0uKuWZB6q4Dji9pxwGnGvYWb6tAzLV9NHf4dt7qeeyea:K9qrXZvmCp7X+Wm4WGutix9lf4Kv4b

Entry address:
0xCB660

Entry point:
55, 8B, EC, 83, C4, F0, B8, 4C, AC, 41, 00, E8, 27, ED, FF, FF, 47, 00, 8B, C0, FF, 25, 6C, 81, 47, 00, 8B, C0, FF, 25, D8, 81, 47, 00, 8B, C0, FF, 25, 68, 81, 47, 00, 8B, C0, FF, 25, 64, 81, 47, 00, 8B, C0, FF, 25, 60, 81, 47, 00, 8B, C0, FF, 25, F0, 81, 47, 00, 8B, C0, FF, 25, EC, 81, 47, 00, 8B, C0, FF, 25, E8, 81, 47, 00, 8B, C0, FF, 25, 5C, 81, 47, 00, 8B, C0, FF, 25, 58, 81, 47, 00, 8B, C0, FF, 25, 00, 82, 47, 00, 8B, C0, FF, 25, FC, 81, 47, 00, 8B, C0, FF, 25, F8, 81, 47, 00, 8B, C0, FF, 25, 54, 81...
 
[+]

Entropy:
6.9542

Developed / compiled with:
Microsoft Visual C++

Code size:
829.5 KB (849,408 bytes)

The file facemoods.exe has been seen being distributed by the following URL.

Remove facemoods.exe - Powered by Reason Core Security