adobeflashplayer12.0.gif

QUANTO SOLUCOES E SISTEMA LTDA

The file adobeflashplayer12.0.gif has been detected as malware by 17 anti-virus scanners.
Publisher:
QUANTO SOLUCOES E SISTEMA LTDA  (signed and verified)

MD5:
5dfd5f6da8af386af61c747d3945d59a

SHA-1:
ca2e199b2ea540dd4c769a133d4f984f1525cf92

SHA-256:
fc03a3594131585f82e53a8cd51430257af791423184d1fa70a177cefd15c3c0

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
4/23/2024 1:20:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.371129
286

avast!
Win32:FakeFlash-B [Trj]
2014.9-160424

AVG
Delf
2017.0.2764

Bitdefender
Gen:Variant.Kazy.371129
1.0.20.575

Comodo Security
UnclassifiedMalware
20033

Emsisoft Anti-Malware
Gen:Variant.Kazy.371129
8.16.04.24.04

ESET NOD32
Win32/Spy.Banker.AAQF (variant)
10.10695

Fortinet FortiGate
W32/Banker.AAQF!tr.spy
4/24/2016

F-Secure
Gen:Variant.Kazy.371129
11.2016-24-04_1

G Data
Gen:Variant.Kazy.371129
16.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.3.0

McAfee
Artemis!5DFD5F6DA8AF
5600.6420

MicroWorld eScan
Gen:Variant.Kazy.371129
17.0.0.345

Qihoo 360 Security
HEUR/Malware.QVM18.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R0C1C0EK514
7.2.115

Trend Micro
TROJ_GEN.R0C1C0EK514
10.465.24

VIPRE Antivirus
Trojan.Win32.Packer.EnigmaProtector1.1X-1.3X
34640

File size:
2.2 MB (2,322,784 bytes)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\adobeflashplayer12.0.gif

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/2/2014 9:00:00 PM

Valid to:
4/3/2015 8:59:59 PM

Subject:
CN=QUANTO SOLUCOES E SISTEMA LTDA, O=QUANTO SOLUCOES E SISTEMA LTDA, L=PRESIDENTE PRUDENTE, S=SAO PAULO, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
00B87EDE3281FFB1EE77DF86B54A8CB0

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:+Y3Vp25/IIogYpCz3+1ugX2m/y+OId//Ky/cKc3uuilC4KMt5GTJ:+Ap2tIhCz3gbKQd//n/c3hiU4Jt5G1

Entry address:
0x92C5

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, A7, 74, 8D, 00, 38, F1, 8E, 0E, 8C, 56, 4D, 7F, 67, 3E, B2, 83, 1A, 5D, 60, 7D, CC, 73, 8F, 80, 1C, D6, 06, 18, 8F, D7, F4, 8A, 88, 41, 2F, 44, AB, 37, 43, AB, D6, 2C, 50, 89, 6B, DE, 3C, D4, 40, 92, 16, 63, 9D, 5D, B9, EF, 2D, 0D, 74, BE, 26, 26, 35, 6F, 92, 11, 15, 48, CC, F5, C5, A9, B6, 91, 74, BD, ED, 78, 1A, 6D, 0C, 11, 09, A7, 10, AC, 31, 12, 98, 74, 4A, B4, 70, 27, 5A, E9, 10, A1, D5, 6D, 09, 8F, 5B, 46...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
571 KB (584,704 bytes)

Remove adobeflashplayer12.0.gif - Powered by Reason Core Security