faith.exe

The application faith.exe has been detected as a potentially unwanted program by 30 anti-malware scanners. The file has been seen being downloaded from download1522.mediafire.com and multiple other hosts.
MD5:
71cf1c15555afaa5b456abdb6537a1c5

SHA-1:
c446fc75c79b4b6cfddb981ad8f133b05fa4aea2

SHA-256:
f95d516cbd2b3fde88c920a402d2afe7803eb34cfa5b24625cb108900ac94f5b

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 6:43:41 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.6295948
1022

Agnitum Outpost
Trojan.Swisyn
7.1.1

Avira AntiVirus
TR/Gendal.3065856
7.11.140.100

avast!
Win32:PUP-gen [PUP]
2014.9-140419

AVG
Generic18
2015.0.3500

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.14419

Bitdefender
Trojan.Generic.6295948
1.0.20.545

Bkav FE
W32.Clod897.Trojan
1.3.0.4959

Clam AntiVirus
Win.Trojan.Inject-2219
0.98/18355

Comodo Security
UnclassifiedMalware
18026

Emsisoft Anti-Malware
Trojan.Generic.6295948
8.14.04.19.09

ESET NOD32
Win32/HackTool.Inject (variant)
8.9618

Fortinet FortiGate
W32/Swisyn.AIXS!tr
4/19/2014

F-Prot
W32/MalwareF.HQLB
v6.4.7.1.166

F-Secure
Trojan.Generic.6295948
11.2014-19-04_7

G Data
Trojan.Generic.6295948
14.4.24

IKARUS anti.virus
Trojan.Win32.Swisyn
t3scan.2.2.29

K7 AntiVirus
Riskware
13.176.11613

McAfee
Artemis!71CF1C15555A
5600.7156

MicroWorld eScan
Trojan.Generic.6295948
15.0.0.327

NANO AntiVirus
Trojan.Win32.Swisyn.bwxee
0.28.0.58720

Norman
Suspicious_Gen2.NXNPD
11.20140419

nProtect
Trojan/W32.Agent.3065856.B
14.03.31.01

Rising Antivirus
PE:Trojan.Win32.Generic.11E8C043!300466243
23.00.65.14417

Sophos
Generic PUA ME
4.98

Trend Micro House Call
TROJ_SPNR.0BIA13
7.2.109

Trend Micro
TROJ_SPNR.0BIA13
10.465.19

VIPRE Antivirus
Trojan.Win32.Generic
27902

ViRobot
Backdoor.Win32.A.Ceckno.3065856
2011.4.7.4223

XVirus List
Win32.Detected
2.4.19

File size:
2.9 MB (3,065,856 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\injector\faith.exe

File PE Metadata
Compilation timestamp:
12/1/2009 2:13:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
24576:ldRVnBk3K7D3yoabZGrrD6NR6GUHFBMVcDakz4D2TwfulU:ZFHsUACt4aTv

Entry address:
0x1480

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 9C, A0, 4D, 00, A1, 8F, A0, 4D, 00, C1, E0, 02, A3, 93, A0, 4D, 00, 52, 6A, 00, E8, 91, 81, 0D, 00, 8B, D0, E8, E6, 42, 0B, 00, 5A, E8, FC, 3E, 0B, 00, E8, C7, 47, 0B, 00, 6A, 00, E8, 94, 58, 0B, 00, 59, 68, 38, A0, 4D, 00, 6A, 00, E8, 6B, 81, 0D, 00, A3, 97, A0, 4D, 00, 6A, 00, E9, 57, DE, 0B, 00, E9, C6, 58, 0B, 00, 33, C0, A0, 81, A0, 4D, 00, C3, A1, 97, A0, 4D, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, EC, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
4.1983

Code size:
868 KB (888,832 bytes)

The file faith.exe has been seen being distributed by the following 3 URLs.

Remove faith.exe - Powered by Reason Core Security