cont4_contabilidad.exe

Cont4-Contabilidad

TETRA INFORMATICA, S.L.

The application cont4_contabilidad.exe, “Cont4-Contabilidad Setup ” by TETRA INFORMATICA, S.L has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.tetrainfo.com.
Publisher:
Tetra Informática, S.L.   (signed by TETRA INFORMATICA, S.L.)

Product:
Cont4-Contabilidad

Description:
Cont4-Contabilidad Setup

MD5:
b4b1a417e790f936861cf12986e42704

SHA-1:
f96681f4674b15d27dca2fdf6b56a68d6078d2b1

SHA-256:
88337b85c8f2fd17c0d4e2db8b9fe58b247ef86aeef2b12feb685de09ca56a24

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/7/2024 1:56:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.3.2.19

File size:
2.2 MB (2,287,368 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\cont4_contabilidad.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
8/26/2016 10:04:38 AM

Valid to:
10/18/2018 12:16:01 PM

Subject:
CN="TETRA INFORMATICA, S.L.", O="TETRA INFORMATICA, S.L.", L=Alcoy, S=Alicante, C=ES

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00D675927003A5D76D

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9953

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file cont4_contabilidad.exe has been seen being distributed by the following URL.

http://www.tetrainfo.com/.../Cont4_contabilidad.exe

Remove cont4_contabilidad.exe - Powered by Reason Core Security