Fifa12.exe

Chrome

The executable Fifa12.exe has been detected as malware by 21 anti-virus scanners. The file has been seen being downloaded from dc117.2shared.com.
Publisher:
Chrome

Product:
Chrome

Version:
1.0.0.0

MD5:
1b77356d69d2ff8a79b439352304c681

SHA-1:
61df79d992dc9da5022bffebdfcdf633a676fe02

SHA-256:
6dd822b9ac183323056c6cdf4d95eba3c65bb0876479e121a1fd5332cce12395

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
11/15/2024 9:59:38 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.41.224

avast!
MSIL:Downloader-DJ [Trj]
2014.9-160330

AVG
Suspicion: unknown virus
2017.0.2789

Bitdefender
Gen:Variant.Kazy.65935
1.0.20.450

Comodo Security
UnclassifiedMalware
13451

Dr.Web
Trojan.DownLoader5.59917
9.0.1.090

Emsisoft Anti-Malware
Trojan-Dropper.Win32.Injector!IK
8.16.03.30.08

ESET NOD32
MSIL/Injector.ZA (variant)
10.7449

Fortinet FortiGate
MSIL/Dropper.GYX!tr
3/30/2016

F-Secure
Gen:Variant.Kazy.65935
11.2016-30-03_4

G Data
Gen:Variant.Kazy.65935
16.3.22

IKARUS anti.virus
Trojan-Dropper.Win32.Injector
t3scan.1.1.122.0

Kaspersky
Trojan-Dropper.Win32.Dapato
14.0.0.438

McAfee
Artemis!1B77356D69D2
5600.6445

Microsoft Security Essentials
Worm:Win32/Ainslot.A
1.163.1557.0

Norman
W32/Suspicious_Gen2.VHCCT
11.20160330

Quick Heal
TrojanDropper.Dapato.bajt
3.16.12.00

Sophos
Mal/Generic-L
4.80

Trend Micro House Call
TROJ_SPNR.30HL12
7.2.90

Trend Micro
TROJ_SPNR.30HL12
10.465.30

VIPRE Antivirus
Trojan.Win32.Generic
12928

File size:
900 KB (921,600 bytes)

Product version:
1.0.0.0

Copyright:
Chrome

Trademarks:
Chrome

Original file name:
Fifa12.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fifa12.exe

File PE Metadata
Compilation timestamp:
4/4/2012 11:38:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:AuGUV226mApKaPB17iscaNt5XnC5+Ja4Vl25WUSUkHVg96k6xjkQ/2BYFqfxDWM:HV22gH5hi5YK5Ma4Vg5wjPuBYFIxqM

Entry address:
0xADBCE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 03, 00, 00, 00, 28, 00, 00, 80, 0E, 00, 00, 00, 80, 00, 00, 80, 10, 00, 00, 00, 98, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 09, 00, 02, 00, 00, 00, B0, 00, 00, 80, 03, 00, 00, 00, C8, 00, 00, 80, 04, 00, 00, 00, E0, 00...
 
[+]

Entropy:
6.7299

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
687 KB (703,488 bytes)

The file Fifa12.exe has been seen being distributed by the following URL.

Remove Fifa12.exe - Powered by Reason Core Security