intimacao-mpf.exe

The executable intimacao-mpf.exe has been detected as malware by 4 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from seguro2.sitebr.net.
MD5:
295b6353e4ec167f97a60d6f0e45afea

SHA-1:
cbd78674818c9cd8803ccba912c8890e58d3b45e

SHA-256:
39d9bd8d0d5749fe095ab91415a9e43be3bc9243699236d7d80c88c3f701eec9

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
8/16/2025 11:34:18 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Trojan.Agent.BJNY
16.07.03

ESET NOD32
MSIL/TrojanDownloader.Banload.DD trojan
7.0.302.0

F-Prot
W32/Msil.AEI (exact, damaged)
4.6.5.141

Norman
Trojan.Agent.BJNY
28.05.2016 13:03:37

File size:
176.9 KB (181,140 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/27/2015 7:27:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:QzJ+lM+sEvWfROJLhfJpreQ00ws/R3b/rz3qh7E+qZd9:nWROJNhpeBUDnqqf9

Entry address:
0x2DE3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
176 KB (180,224 bytes)

The file intimacao-mpf.exe has been seen being distributed by the following URL.

Remove intimacao-mpf.exe - Powered by Reason Core Security