calledrun.exe

WALISON BARBOSA 04293554165

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘callset’.
Publisher:
WALISON BARBOSA 04293554165  (signed and verified)

Version:
1.0.0.0

MD5:
1325237184667573727f29d56aedbea4

SHA-1:
ae9dc5ab7a263f1ebb4c51c380e02f2670eefa6b

SHA-256:
9caecc1941272a35101830d96372ecf5f59e9870130f08d5a69b50648573f07f

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
6/19/2025 5:27:14 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Spy.Banker.ADDG trojan
6.3.12010.0

File size:
2.4 MB (2,538,592 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\public\calledrun.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/12/2017 10:00:00 PM

Valid to:
1/13/2018 9:59:59 PM

Subject:
CN=WALISON BARBOSA 04293554165, O=WALISON BARBOSA 04293554165, STREET=AV ANHANGUERA 7840 LOJA 119, L=GOIANIA, S=GOIAS, PostalCode=74.503-100, C=BR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
753BAB040D3646BC92680D068B9C896D

File PE Metadata
Compilation timestamp:
2/22/2017 12:48:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1952B8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 48, D1, 58, 00, E8, 40, 52, E7, FF, A1, 44, EA, 59, 00, 8B, 00, E8, E8, 8A, F2, FF, A1, 44, EA, 59, 00, 8B, 00, B2, 01, E8, 16, A8, F2, FF, A1, 44, EA, 59, 00, 8B, 00, BA, 28, 53, 59, 00, E8, E5, 84, F2, FF, 8B, 0D, F4, EC, 59, 00, A1, 44, EA, 59, 00, 8B, 00, 8B, 15, 14, 72, 57, 00, E8, C9, 8A, F2, FF, A1, 44, EA, 59, 00, 8B, 00, E8, 0D, 8C, F2, FF, E8, 48, 0C, E7, FF, B0, 04, 02, 00, FF, FF, FF, FF, 13, 00, 00, 00, 72, 00, 65, 00, 61, 00, 64, 00, 6D, 00, 65, 00, 20, 00, 73, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.6 MB (1,653,760 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
callset

Command:
C:\users\public\calledrun.exe


Scan calledrun.exe - Powered by Reason Core Security