wi fi pirate.exe

Wi Fi Pirate

http://wi-fi-pirate.ru

The application wi fi pirate.exe, “Программа для взлома Wi FI” has been detected as a potentially unwanted program by 23 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from 4omy40zdcvoecj6.dredivo.ru.
Publisher:
http://wi-fi-pirate.ru

Product:
Wi Fi Pirate

Description:
Программа для взлома Wi FI

Version:
13.0.4.2

MD5:
8f9d053f4b2e4566fb20d336faed1af5

SHA-1:
4d1a64a8cdb5ee5b572ff9b2049cdff3b1b36b6e

SHA-256:
51aea4eec4a579c60e50181850b5bda5bda39f99e78665bbd56a2ab47819e053

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
1/15/2025 8:53:49 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDV.949032
903

Agnitum Outpost
Trojan.PWS.Agent
7.1.1

avast!
Win32:PUP-gen [PUP]
2014.9-140815

AVG
Generic32
2015.0.3381

Baidu Antivirus
Trojan.Win32.Banker
4.0.3.14815

Bitdefender
Trojan.GenericKDV.949032
1.0.20.1135

Comodo Security
UnclassifiedMalware
17819

Emsisoft Anti-Malware
Trojan.GenericKDV.949032
8.14.08.15.11

Fortinet FortiGate
W32/Agent.PGF!tr
8/15/2014

F-Secure
Trojan.GenericKDV.949032
11.2014-15-08_6

G Data
Trojan.GenericKDV.949032
14.8.24

IKARUS anti.virus
Trojan-Banker.Win32.Agent
t3scan.2.2.29

K7 AntiVirus
Riskware
13.176.11226

Kaspersky
Trojan-Banker.Win32.Agent
14.0.0.3400

McAfee
Artemis!8F9D053F4B2E
5600.7037

MicroWorld eScan
Trojan.GenericKDV.949032
15.0.0.681

nProtect
Trojan.GenericKDV.949032
14.02.20.01

Panda Antivirus
Trj/CI.A
14.08.15.11

Trend Micro House Call
TROJ_SPNV.01KH13
7.2.227

Trend Micro
TROJ_SPNV.01KH13
10.465.15

Vba32 AntiVirus
TrojanBanker.Agent
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
26680

ViRobot
Trojan.Win32.A.Agent.4015104
2011.4.7.4223

File size:
3.8 MB (4,015,104 bytes)

Product version:
13.0.4.2

Copyright:
http://wi-fi-pirate.ru

Trademarks:
http://wi-fi-pirate.ru

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wi fi pirate.exe

File PE Metadata
Compilation timestamp:
2/19/2013 12:19:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:vUAkmX2GYHZh+wG2rG7Xa1Ip0GP0RP03nPzy:8AkmxYHewG2C7XOIWGcin

Entry address:
0x192C3C

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 80, FA, 58, 00, E8, DF, 4A, E7, FF, 8B, 1D, CC, 96, 59, 00, 8B, 03, E8, F2, 91, ED, FF, 8B, 03, B2, 01, E8, 1D, B0, ED, FF, 8B, 0D, 04, 95, 59, 00, 8B, 03, 8B, 15, BC, C9, 58, 00, E8, EE, 91, ED, FF, 8B, 0D, 88, 92, 59, 00, 8B, 03, 8B, 15, 28, A0, 58, 00, E8, DB, 91, ED, FF, 8B, 0D, 68, 98, 59, 00, 8B, 03, 8B, 15, A8, 9D, 58, 00, E8, C8, 91, ED, FF, 8B, 03, E8, 41, 92, ED, FF, 5B, E8, 3F, 25, E7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.6 MB (1,642,496 bytes)

The file wi fi pirate.exe has been seen being distributed by the following URL.

Remove wi fi pirate.exe - Powered by Reason Core Security