backupbusiness.exe

EBS Empresa Brasileira de Sistemas Ltda

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BackupBusiness’.
Publisher:

Version:
1.0.1.1

MD5:
cace6146ca78813296104f448d47a44d

SHA-1:
9a11dfd7da5542d790bc5f13fa93fbbb0914f7c5

SHA-256:
7713b07279fcabf478bd92921bc8166fe9b9f3c14933de91901a0a9bb0e870bf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/14/2024 7:28:59 AM UTC  (today)

File size:
927.8 KB (950,056 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/2/2014 9:00:00 PM

Valid to:
6/3/2015 8:59:59 PM

Subject:
CN=EBS Empresa Brasileira de Sistemas Ltda, O=EBS Empresa Brasileira de Sistemas Ltda, L=Curitiba, S=Parana, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
65306F021CECEE905E76B26AD87D8E0D

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x2C6FE0

Entry point:
60, BE, 00, 80, 5E, 00, 8D, BE, 00, 90, E1, FF, C7, 87, D0, 10, 23, 00, 28, 75, 0C, A3, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
896 KB (917,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BackupBusiness

Command:
C:\ger_backup_business\backupbusiness.exe


Scan backupbusiness.exe - Powered by Reason Core Security