b9fac139.exe

SOFTWARE CENTER INFORMATICA LTDA - ME

The executable b9fac139.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
SOFTWARE CENTER INFORMATICA LTDA - ME  (signed and verified)

MD5:
85bb761d6327d3ea092fdb336e6d4f73

SHA-1:
a933d1111de9960fe302167df4d2d8457dc655de

SHA-256:
bd38cbd197faaeb85b5ab0c0497922c546dff381a88c7dae89fd2c2c1a4ca2a0

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/5/2024 1:57:46 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.17.12

File size:
9.9 MB (10,431,328 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\b9fac139.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/24/2015 2:34:16 PM

Valid to:
4/24/2016 2:34:16 PM

Subject:
CN=SOFTWARE CENTER INFORMATICA LTDA - ME, OU=TI, O=SOFTWARE CENTER INFORMATICA LTDA - ME, L=JUQUITIBA, S=SAO PAULO, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E4364E01A7278CB5E2EEB812C5E418BA

File PE Metadata
Compilation timestamp:
1/15/2010 9:27:14 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.24

Entry address:
0x1B638D1

Entry point:
E9, CA, DB, FF, FF, F5, F9, C0, C0, 06, C6, 44, 24, 04, 88, E9, 56, FA, FF, FF, 23, 48, C0, EE, A2, 16, 40, 71, 9B, 10, C7, 8A, B3, 39, CF, 05, AB, 80, EB, 40, BB, F1, EF, C5, 8F, 44, CB, C0, 87, 6D, FF, 95, 97, 3D, 4C, 3A, B2, E4, 22, D7, 2E, DB, AE, C4, C6, AC, 5C, 29, 4C, 1C, 16, 21, 12, CE, 1B, 23, E8, 45, AF, 44, F7, 5D, 07, 0F, F0, 44, 56, B5, CA, 45, 9B, 49, 2B, 44, CF, 7F, 63, E3, 1B, 9A, 63, A4, 6D, 87, 3B, CA, 51, 73, C6, 77, 97, 4E, 1D, F7, BD, 23, FB, 03, F9, 01, 69, D9, D3, 4C, CB, 5A, AB, 51...
 
[+]

Entropy:
7.8069

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
29.5 KB (30,208 bytes)

Remove b9fac139.exe - Powered by Reason Core Security