calcpena.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from onedrive.live.com and multiple other hosts.
MD5:
7eff37d4efae6a6421dd058a3e91de8a

SHA-1:
f7498be0dc4f4ffb5b7a80e9d233727b92538f00

SHA-256:
0038a7bb3fe49938e80ac7d0198f4cf96b03abd4f029ee1c07f01ce11b67f47a

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/26/2024 12:07:39 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Pedka
1.3.0.4613

Emsisoft Anti-Malware
Trojan.Ransom.ADC
8.13.12.30.01

File size:
590.5 KB (604,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\calcpena.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:64eQ/zXGwwTAC2o3oyp4n5I+YSAehImDtKrzS/KjSxB8dvD:6tQ/ih/457vZDtIS/b8d

Entry address:
0x7AF64

Entry point:
55, 8B, EC, 83, C4, F4, 53, B8, C4, AD, 47, 00, E8, 6B, B4, F8, FF, 8B, 1D, 34, DA, 47, 00, 8B, 03, E8, 66, 08, FD, FF, 8B, 0D, 50, D8, 47, 00, 8B, 03, 8B, 15, 80, 60, 47, 00, E8, 6B, 08, FD, FF, 8B, 0D, 28, DA, 47, 00, 8B, 03, 8B, 15, C8, FB, 45, 00, E8, 58, 08, FD, FF, 8B, 0D, 0C, DA, 47, 00, 8B, 03, 8B, 15, B4, FD, 45, 00, E8, 45, 08, FD, FF, 8B, 0D, 58, D8, 47, 00, 8B, 03, 8B, 15, 94, 03, 46, 00, E8, 32, 08, FD, FF, 8B, 0D, D4, D9, 47, 00, 8B, 03, 8B, 15, 4C, 42, 47, 00, E8, 1F, 08, FD, FF, 8B, 0D, F0...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
488.5 KB (500,224 bytes)

The file calcpena.exe has been seen being distributed by the following 10 URLs.

https://onedrive.live.com/.../BTmGeU=4&ithint=.exe

http://www.mppe.mp.br/siteantigo/siteantigo.mppe.mp.br/uploads/l3_-OxYJwM3p-owiO-nCew/.../calcpena.exe

http://www.mpac.mp.br/menu-principal/coordenadorias/.../?dl_id=132

http://www.mpac.mp.br/.../?dl_id=132

Scan calcpena.exe - Powered by Reason Core Security