instvc.exe

FusionTech Visual Contab

ICP-Brasil

The application instvc.exe, “Folha de Pagamento, Escrita Fiscal, Contabilidade e Livro Ca” by ICP-Brasil has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.fusiontech.com.br.
Publisher:
FusionTech® Sistemas   (signed by ICP-Brasil)

Product:
FusionTech® Visual Contab

Description:
Folha de Pagamento, Escrita Fiscal, Contabilidade e Livro Ca

Version:
2016

MD5:
0bd50b1edcc781f6f53e338dd6be453c

SHA-1:
70fde7e2695b8e55251ef3da3e32289957cc3931

SHA-256:
77c0f0b78066b22a11dd8266f78f571206bb13d1ca6186233946741bb1ab8e21

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/3/2024 1:52:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.11.30.4

File size:
24.5 MB (25,638,208 bytes)

Product version:
2016

Copyright:
ATENÇÃO: Execute a instalação como ADMINISTRADOR se for usuário do Windows 7 ou 8 ou 10 - FusionTech

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\instvc.exe

Digital Signature
Signed by:

Authority:
ICP-Brasil

Valid from:
11/17/2015 4:38:07 PM

Valid to:
11/16/2016 4:38:07 PM

Subject:
CN=FusionTech Sistemas, OU=Secretaria da Receita Federal do Brasil - RFB, O=ICP-Brasil, S=Some-State, C=BR

Issuer:
CN=FusionTech Sistemas, OU=Secretaria da Receita Federal do Brasil - RFB, O=ICP-Brasil, S=Some-State, C=BR

Serial number:
00FAB928826E2236DF

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:LHfj1JK4T50hbBJci0HaTM+vZxXnLQmAryZbZcqD36sDjFQYFnBODfZJKOdufYcQ:LHr8bBiHyPXJKq2sDjjuDKAufYcQ

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file instvc.exe has been seen being distributed by the following URL.

http://www.fusiontech.com.br/.../InstVC.exe

Remove instvc.exe - Powered by Reason Core Security