huanyca.exe

WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA

The executable huanyca.exe has been detected as malware by 27 anti-virus scanners.
Publisher:
Steves Corp USA  (signed by WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA)

Description:
App Aplle Br New

Version:
4.0.2.0

MD5:
e060998bb6f54fce61697fc4b885039f

SHA-1:
c682a4b447721da1e33ddda0de2728785a78653e

SHA-256:
bb894507abb9fa7189bab500538a8162d0f7576ff6605892fa51657d81c36bb8

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/26/2024 3:16:10 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.41101
544

Agnitum Outpost
Trojan.DL.Banload
7.1.1

avast!
Win32:Malware-gen
2014.9-150810

AVG
Win32/Blacked
2016.0.3022

Bitdefender
Gen:Variant.Symmi.41101
1.0.20.1110

Comodo Security
UnclassifiedMalware
21615

Dr.Web
Trojan.DownLoader9.60844
9.0.1.0222

Emsisoft Anti-Malware
Gen:Variant.Symmi.41101
8.15.08.10.02

ESET NOD32
Win32/TrojanDownloader.Banload.SYC (variant)
9.11412

Fortinet FortiGate
W32/Banload.SYC!tr.dldr
8/10/2015

F-Secure
Gen:Variant.Symmi.41101
11.2015-10-08_2

G Data
Gen:Variant.Symmi.41101
15.8.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.9.0

Kaspersky
Trojan-Dropper.Win32.Dapato
14.0.0.1605

Malwarebytes
Trojan.MSIL.Agent
v2015.08.10.02

McAfee
Artemis!E060998BB6F5
5600.6678

Microsoft Security Essentials
TrojanSpy:Win32/Bancos.AKZ
1.1.11502.0

MicroWorld eScan
Gen:Variant.Symmi.41101
16.0.0.666

Norman
Troj_Generic.TDJOD
11.20150810

Panda Antivirus
Trj/Genetic.gen
15.08.10.02

Qihoo 360 Security
Win32/Trojan.Dropper.4b5
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.11FJ14
7.2.222

Trend Micro
TROJ_SPNR.11FJ14
10.465.10

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
38974

Zillya! Antivirus
Dropper.Dapato.Win32.24116
2.0.0.2123

File size:
2.3 MB (2,457,696 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\huanyca.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/5/2014 9:00:00 PM

Valid to:
3/6/2015 8:59:59 PM

Subject:
CN=WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA, O=WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA, STREET="RUA RUBIAO JUNIOR, 2386", STREET=PISO SUPERIOR, STREET=PARQUE INDUSTRIAL, L=SAO JOSE DO RIO PRETO, S=SAO PAULO, PostalCode=15025080, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0B0D17EC1449B4B2D38FCB0F20FBCD3A

File PE Metadata
Compilation timestamp:
3/7/2014 3:18:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:RUIt/IV9sfNQ2keHipElIXw7Zcr5xvCo9RWmr3j/02dkg6pxFK8nxEWWKA8EyPpP:bZIMCEM9A7Zcr5pNPrb02gxoZkiyRtEq

Entry address:
0x59AEA

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 92, C8, 69, 00, 3C, A1, 40, F2, 97, 47, F9, 1C, 1A, E7, 10, 4E, 49, 81, A7, 44, 6D, 04, 61, 8E, E9, 44, 65, DC, 7A, F6, A4, E4, 22, 47, F8, A0, 1E, 3D, 05, 54, 4D, 19, C2, D9, 1C, 66, E6, D3, FA, 9B, 0E, 67, CD, E6, 5B, D6, 49, B6, 0A, 09, 8B, 43, 9B, 86, D0, 83, CF, 9A, B3, D4, 66, CB, B0, 7C, 16, AC, 19, C8, 07, 87, B7, 6E, 0C, AD, AF, 67, 0F, 43, E9, C1, CB, 06, B6, F2, 2A, 03, 0B, A2, 23, 25, 79, BB, 02, 8E...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.9 MB (3,004,928 bytes)

Remove huanyca.exe - Powered by Reason Core Security