abrir anexo.exe

The executable abrir anexo.exe has been detected as malware by 18 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from storage.googleapis.com.
MD5:
17292bf9957355636430e5bd5e008bc7

SHA-1:
8657a771998ae890a135d2c4449eeeb967c3fb3b

SHA-256:
2f2400663cb105f72d3f7922265348f1222137aede8e2903a685edd43fe9984a

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/18/2024 6:03:42 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2495801
381

Arcabit
Trojan.Generic.D261539
1.0.0.425

avast!
Win32:Malware-gen
2014.9-160119

AVG
Downloader.Banload2
2017.0.2859

Baidu Antivirus
Trojan.Win32.Banload
4.0.3.16119

Bitdefender
Trojan.GenericKD.2495801
1.0.20.95

Emsisoft Anti-Malware
Trojan.GenericKD.2495801
8.16.01.19.06

ESET NOD32
Win32/TrojanDownloader.Banload.VXF (variant)
10.11817

Fortinet FortiGate
W32/Banload.VXF!tr.dldr
1/19/2016

F-Secure
Trojan.GenericKD.2495801
11.2016-19-01_3

G Data
Trojan.GenericKD.2495801
16.1.25

Kaspersky
Trojan-Downloader.Win32.Banload
14.0.0.791

McAfee
Artemis!17292BF99573
5600.6515

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!bit
1.1.11701.0

MicroWorld eScan
Trojan.GenericKD.2495801
17.0.0.57

Panda Antivirus
Trj/CI.A
16.01.19.06

Sophos
Mal/Behav-130
4.98

VIPRE Antivirus
Trojan.Win32.Generic
41304

File size:
594 KB (608,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\abrir anexo.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:9bsYWIbWvGHrjFKNTl759H5ywTLs6ADdwiOX3eQlFg:9IVIEGHrpK53DyoADdw/XuQ4

Entry address:
0x7BC88

Entry point:
55, 8B, EC, 83, C4, F0, B8, F0, B8, 47, 00, E8, A4, A4, F8, FF, A1, 28, DF, 47, 00, 8B, 00, E8, C0, AE, FD, FF, A1, 28, DF, 47, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, C4, E0, 47, 00, A1, 28, DF, 47, 00, 8B, 00, 8B, 15, 60, AD, 47, 00, E8, B5, AE, FD, FF, A1, 28, DF, 47, 00, 8B, 00, E8, 29, AF, FD, FF, E8, 24, 81, F8, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
491.5 KB (503,296 bytes)

The file abrir anexo.exe has been seen being distributed by the following URL.

Remove abrir anexo.exe - Powered by Reason Core Security