FIFA14.exe

WindowsApplication1

The executable FIFA14.exe has been detected as malware by 7 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from cluster011.ovh.net and multiple other hosts.
Publisher:
Microsoft*  (Invalid match)

Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
1acba8b0dcd9142edb0992d6348cf588

SHA-1:
0afd8705ca6cc3662c970bede42a0efa4acd26d3

SHA-256:
bb54908a5e753ab2c1cc70864264dc8d82f26fd212d1c1c4045c94fc6dbc915c

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/27/2024 7:24:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11755377
818

Bitdefender
Trojan.Generic.11755377
1.0.20.1565

Emsisoft Anti-Malware
Trojan.Generic.11755377
8.14.11.09.08

F-Secure
Trojan.Generic.11755377
11.2014-09-11_1

G Data
Trojan.Generic.11755377
14.11.24

MicroWorld eScan
Trojan.Generic.11755377
15.0.0.939

nProtect
Trojan.Generic.11755377
14.09.28.01

File size:
5.5 MB (5,793,792 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2014

Original file name:
FIFA14.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fifa14.exe

File PE Metadata
Compilation timestamp:
7/23/2014 3:27:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:xtNLFNL+WmDnnEK+CVyN1Rn66lfXMuI8yMHhVqhvldJE6SWc92YT9wiaQYBr0eOD:tL3L+5nHyNDntlfMl8p2tE6Lc9B9wRQs

Entry address:
0x583DEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 7E, 0F, CF, 53, 00, 00, 00, 00, 02, 00, 00, 00, 79, 00, 00, 00, 1C, 40, 58, 00, 1C, 22, 58, 00, 52, 53, 44, 53, B8, B9, 13, F1, 74, 67, C1, 43, 95, 4F, 10, B6, 24, 04, 40, 76, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 57, 6F, 6A, 74, 65, 6B, 5C, 44, 6F, 77, 6E, 6C, 6F, 61, 64, 73, 5C, 44, 65, 73, 6B, 74, 6F, 70, 20, 28, 37, 29, 5C, 49, 6E, 73, 74, 61, 6C, 61, 74, 6F, 72, 35, 5C, 49, 6E, 73, 74, 61, 6C, 61, 74...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
5.5 MB (5,774,848 bytes)

The file FIFA14.exe has been seen being distributed by the following 3 URLs.

Remove FIFA14.exe - Powered by Reason Core Security