cashnback.exe

Aplicação do Cash 'n Back

RBM SOLUCOES EM INFORMATICA LTDA - EPP

The application cashnback.exe by RBM SOLUCOES EM INFORMATICAA - EPP has been detected as a potentially unwanted program by 2 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Aplicação do Cash 'n Back”. This file is typically installed with the program Cash 'n Back by RBM Solutions.
Publisher:
CNB Technologies LLC  (signed by RBM SOLUCOES EM INFORMATICA LTDA - EPP)

Product:
Aplicação do Cash 'n Back

Version:
1.0.6

MD5:
646e51a55ec8abccb8eec52968dfb5e7

SHA-1:
f5a02c5c89b8971f1430dceeeb2f44f6a2099f71

SHA-256:
e8072abbc9a4afebba9d483bf4541ca768e88ad52b9e2d50fd21b4e66a4e7517

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:00:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Cashback.RBMSOLUCOESEMINFORMATICAAEPP.Meta (M)
16.1.28.0

Trend Micro House Call
Suspicious_GEN.F47V0722
7.2.205

File size:
396.1 KB (405,616 bytes)

Product version:
1.0.6

Copyright:
(c) CNB Technologies LLC. All rights reserved.

Original file name:
CashNBack

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\rbm\cashnback\cashnback.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/13/2014 10:00:00 PM

Valid to:
12/9/2014 10:00:00 AM

Subject:
CN=RBM SOLUCOES EM INFORMATICA LTDA - EPP, O=RBM SOLUCOES EM INFORMATICA LTDA - EPP, L=São Paulo, S=São Paulo, C=BR, PostalCode=04125120, STREET="Rua Delmira Ferreira, 178", SERIALNUMBER=17834147000180, OID.1.3.6.1.4.1.311.60.2.1.3=BR, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0159F824AE51D90E04B4ACA79A1BB571

File PE Metadata
Compilation timestamp:
7/11/2014 5:42:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
6144:UCUSShiKz/b1uloEAxmqxm3lRXdKPLFv+/ZZo7b0KkfSZnl:UCBSDg6EcmcmV0+/ZZoXZl

Entry address:
0x26790

Entry point:
E8, E2, A2, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, 83, EC, 2C, A1, F8, E7, 44, 00, 33, C5, 89, 45, FC, 56, FF, 75, 0C, 8B, 75, 08, 8D, 4D, D4, E8, 84, E5, FF, FF, 85, F6, 75, 14, E8, 8A, 10, 00, 00, C7, 00, 16, 00, 00, 00, E8, 6F, 76, 00, 00, D9, EE, EB, 4B, 8B, 55, D4, 83, 7A, 74, 01, 7E, 17, 8D, 45, D4, 50, 0F, B6, 06, 6A, 08, 50, E8, 89, 55, 00, 00, 8B, 55, D4, 83, C4, 0C, EB, 10, 0F, B6, 0E, 8B, 82, 90, 00, 00, 00, 0F, B7, 04, 48, 83, E0, 08, 85, C0, 74, 03, 46, EB, CC, 8D, 45, D4, 50, 8D, 45, E4, 56...
 
[+]

Code size:
245.5 KB (251,392 bytes)

Service
Display name:
Aplicação do Cash 'n Back

Service name:
CashNBack Application

Type:
Win32OwnProcess


The file cashnback.exe has been discovered within the following program.

Cash 'n Back  by RBM Solutions
ncupons.com.br/cashback
About 1% of users remove it
 
Powered by Should I Remove It?

Remove cashnback.exe - Powered by Reason Core Security