gerenciador_de_aplicativos_[faab-9cfa-1469] - copia.exe

Gerenciador de Aplicativos

FS VAS PARTICIPACOES E SERVICOS DE TECNOLOGIA E TELECOMUNICACOES

This is a setup program which is used to install the application. The file has been seen being downloaded from gvt.whitelabel.com.br.
Publisher:
GVT  (signed by FS VAS PARTICIPACOES E SERVICOS DE TECNOLOGIA E TELECOMUNICACOES)

Product:
Gerenciador de Aplicativos

Version:
2.0.0

MD5:
867fdae511f0753f1233e1b44be65697

SHA-1:
f03da044aaa727da67c566165f9eb2e9f3210856

SHA-256:
4bb76ee1e93da4eff22a4b89d3d441a907af13528f4ab1cc553daea04ce77413

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 8:15:12 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
PUA.DownloadAdmin
t3scan.1.9.5.0

Vba32 AntiVirus
Downloader.DownloAdmin
3.12.26.4

Zillya! Antivirus
Downloader.DownloAdmin.Win32.499
2.0.0.2417

File size:
2.3 MB (2,384,880 bytes)

Product version:
2.0.0

Copyright:
Copyright (C) 2015 GVT

Original file name:
gerenciador_de_aplicativos.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\sociologia magrela\gerenciador_de_aplicativos_[faab-9cfa-1469] - copia.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
5/7/2014 2:02:40 PM

Valid to:
5/7/2017 2:02:40 PM

Subject:
CN=FS VAS PARTICIPACOES E SERVICOS DE TECNOLOGIA E TELECOMUNICACOES, O=FS VAS PARTICIPACOES E SERVICOS DE TECNOLOGIA E TELECOMUNICACOES, L=Sao Paulo, S=SP, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121AAAF7185434AF2EF05A4E7E26296B087

File PE Metadata
Compilation timestamp:
4/2/2015 10:32:03 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:wyl9PxwdVdEJFyQql+MZ5cRimrxvgWXFjus6RRE1KeRy5W:wm96dVduyQql+vVFrZus6vh35W

Entry address:
0x322EE

Entry point:
E8, B9, 9F, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 04, 8B, 4C, 24, 08, F7, C2, 03, 00, 00, 00, 75, 3C, 8B, 02, 3A, 01, 75, 2E, 0A, C0, 74, 26, 3A, 61, 01, 75, 25, 0A, E4, 74, 1D, C1, E8, 10, 3A, 41, 02, 75, 19, 0A, C0, 74, 11, 3A, 61, 03, 75, 10, 83, C1, 04, 83, C2, 04, 0A, E4, 75, D2, 8B, FF, 33, C0, C3, 90, 1B, C0, D1, E0, 83, C0, 01, C3, F7, C2, 01, 00, 00, 00, 74, 18, 8A, 02, 83, C2, 01, 3A, 01, 75, E7, 83, C1, 01, 0A, C0, 74, DC, F7, C2, 02, 00, 00, 00, 74, A4, 66, 8B...
 
[+]

Code size:
280 KB (286,720 bytes)

The file gerenciador_de_aplicativos_[faab-9cfa-1469] - copia.exe has been seen being distributed by the following URL.