fbvdupdate7.1.exe

VIDEO TECH PRODUCOES LTDA - ME

The executable fbvdupdate7.1.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from goo.gl.
Publisher:
VIDEO TECH PRODUCOES LTDA - ME  (signed and verified)

MD5:
f8e44b460a66bf4f54e21cd805974d53

SHA-1:
5e28fa5d69da16103f38b1e84e1fd4dfd6a9e348

SHA-256:
a843e026f9ab1aa02d6770d45dd72c3b79d3592c4a41eff8954e24ecca4cbf8b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 6:40:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.13.4

File size:
1.4 MB (1,421,080 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fbvdupdate7.1.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/1/2013 9:00:00 PM

Valid to:
7/2/2014 8:59:59 PM

Subject:
CN=VIDEO TECH PRODUCOES LTDA - ME, O=VIDEO TECH PRODUCOES LTDA - ME, L=Florianópolis, S=Santa Catarina, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
75BF24911D0DEAA1302738F5948159B1

File PE Metadata
Compilation timestamp:
10/25/2013 12:02:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x258000

Entry point:
EB, 03, B9, EF, 46, 50, EB, 03, 18, B0, 86, E8, 14, 00, 00, 00, EB, 02, 15, 5F, EB, 05, 6B, 8C, 44, DC, 70, 33, C0, 70, 40, 71, 6C, EB, 01, 3E, EB, 05, D2, B0, 16, 71, 07, B8, 21, 48, F4, F6, EB, 03, 0A, 35, A8, EB, 05, DC, B6, 17, 3C, 16, 05, DF, B7, 0B, 09, EB, 02, D0, B0, 75, 46, EB, 03, F2, D1, 56, 64, FF, 30, EB, 05, 3A, 88, AC, 79, 94, 64, 89, 20, EB, 04, EA, 3B, 96, DF, EB, 04, BD, 4B, 46, 76, 8B, 10, EB, 04, 15, 5A, 15, 45, 64, 8F, 00, EB, 05, FE, 11, BD, 23, 10, 83, C4, 04, EB, 05, F2, E9, 27, 72...
 
[+]

Code size:
110 KB (112,640 bytes)

The file fbvdupdate7.1.exe has been seen being distributed by the following URL.

https://goo.gl/R6t1N7

Remove fbvdupdate7.1.exe - Powered by Reason Core Security