asulaunch.tmp

WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA

The file asulaunch.tmp has been detected as malware by 28 anti-virus scanners.
Publisher:

MD5:
5c66c5ec5906545cff78fa7b344354c1

SHA-1:
d726386f2176717b7f9a21fb9561520adde1a167

SHA-256:
90c73cf741b5b5e9f8f3262ae29b0205528cbca8791616b359f8c8bfca07d9b6

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/25/2024 3:49:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.55049
-22

Agnitum Outpost
Trojan.PWS.Banker
7.1.1

AhnLab V3 Security
Malware/Win32.Generic
2015.12.12

Avira AntiVirus
TR/Strictor.55049.5
8.3.2.4

Arcabit
Trojan.Strictor.DD709
1.0.0.629

avast!
Win32:Banker-KTY [Trj]
2014.9-170226

AVG
Luhe.Fiha.A
2018.0.2456

Bitdefender
Gen:Variant.Strictor.55049
1.0.20.285

Comodo Security
UnclassifiedMalware
23732

Dr.Web
Trojan.PWS.Banker1.13677
9.0.1.057

Emsisoft Anti-Malware
Gen:Variant.Strictor.55049
8.17.02.26.05

ESET NOD32
Win32/Spy.Banker.AAWU (variant)
11.12710

Fortinet FortiGate
W32/Banker.TDVC!tr
2/26/2017

F-Secure
Gen:Variant.Strictor.55049
11.2017-26-02_1

G Data
Gen:Variant.Strictor.55049
17.2.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

K7 AntiVirus
Spyware
13.212.18087

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1226

McAfee
GenericR-ATY!5C66C5EC5906
5600.6112

MicroWorld eScan
Gen:Variant.Strictor.55049
18.0.0.171

NANO AntiVirus
Trojan.Win32.Banker1.cxbbit
1.0.10.5081

Panda Antivirus
Trj/CI.A
17.02.26.05

Qihoo 360 Security
Win32/Trojan.6da
1.0.0.1077

Quick Heal
TrojanBanker.Banker.r9
2.17.14.00

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
45774

ViRobot
Trojan.Win32.A.Banker.813664[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Banker.Win32.94770
2.0.0.2560

File size:
794.6 KB (813,664 bytes)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\asulaunch.tmp

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/5/2014 9:00:00 PM

Valid to:
3/6/2015 8:59:59 PM

Subject:
CN=WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA, O=WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA, STREET="RUA RUBIAO JUNIOR, 2386", STREET=PISO SUPERIOR, STREET=PARQUE INDUSTRIAL, L=SAO JOSE DO RIO PRETO, S=SAO PAULO, PostalCode=15025080, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0B0D17EC1449B4B2D38FCB0F20FBCD3A

File PE Metadata
Compilation timestamp:
4/12/2014 4:48:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA8B50

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, 9C, 73, 4A, 00, E8, AB, E4, F5, FF, 33, C0, 55, 68, 01, 8C, 4A, 00, 64, FF, 30, 64, 89, 20, A1, 94, EF, 4A, 00, 8B, 00, E8, D5, 77, FB, FF, A1, 94, EF, 4A, 00, 8B, 00, B2, 01, E8, 7F, 96, FB, FF, 8B, 0D, 40, EE, 4A, 00, A1, 94, EF, 4A, 00, 8B, 00, 8B, 15, DC, 78, 49, 00, E8, C7, 77, FB, FF, A1, 94, EF, 4A, 00, 8B, 00, C6, 40, 5B, 00, A1, 94, EF, 4A, 00, 8B, 00, E8, E8, 78, FB, FF, A1, 40, EE, 4A, 00, 8B, 00, 80, B8, 78, 03, 00, 00, 00, 74, 1F, 6A, 00, 8D, 55...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
669.5 KB (685,568 bytes)

Remove asulaunch.tmp - Powered by Reason Core Security