photoscape-12505-dp.exe

Pofecas

The executable photoscape-12505-dp.exe, “Pofecas Setup ” has been detected as malware by 6 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.funsafebulk.com.
Product:
Pofecas

Description:
Pofecas Setup

MD5:
04c28ce55d95bfbcd503d1c723f86b6c

SHA-1:
3e18a9e0977fc4d18ec12ddd78361f50075c4c0b

SHA-256:
e6df7cce1469c4e7492d76b743e945b3832efa67ea43d32d0b5c14993b627391

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/27/2024 5:55:27 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160518-2

AVG
Win32/Parite
2015.0.4604

ESET NOD32
Win32/Parite.B virus
7.0.302.0

F-Prot
W32/Parite.B
4.6.5.141

Kaspersky
Virus.Win32.Parite
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.2453.0

File size:
1.1 MB (1,159,132 bytes)

Product version:
5.2

Copyright:
Stub

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\photoscape-12505-dp.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qO7lcHcZYwySG9c+bYoLXOM2x9zEtDe2laiC6HnNbvDDyp7DwpTFI0VCa:qOZccZ2SGWEeM2v8C24yHndDDyBkn

Entry address:
0x1A000

Entry point:
90, 90, B9, F3, 17, 0C, 00, 90, 68, 22, A0, 41, 00, 5E, BF, 98, 05, 00, 00, 90, 90, FF, 34, 3E, 31, 0C, 24, 8F, 04, 3E, 90, 4F, 83, EF, 03, 75, F0, 90, 1B, 6A, 0D, 00, F3, 17, 0C, 00, F3, 17, 4C, 00, 6B, BD, 0C, 00, 63, EE, 02, 00, 2F, E8, 02, 00, F3, A7, 0E, 00, 0C, E8, F3, FF, 47, F7, 4C, 00, 9F, F5, 4C, 00, 77, F5, 4C, 00, F3, 17, 0C, 00, F3, 17, 0C, 00, F3, 17, 0C, 00, 47, BD, 0C, 00, 99, F5, 0C, 00, 71, F5, 0C, 00, F3, 17, 0C, 00, F3, 17, 0C, 00, F3, 17, 0C, 00, F3, 17, 0C, 00, EF, F6, 4C, 00, F3, 17...
 
[+]

Code size:
40.5 KB (41,472 bytes)

The file photoscape-12505-dp.exe has been seen being distributed by the following URL.

Remove photoscape-12505-dp.exe - Powered by Reason Core Security