OPCreditBillHistory.EXE

patientBillwise

BTS

The executable OPCreditBillHistory.EXE has been detected as malware by 3 anti-virus scanners.
Publisher:
BTS

Product:
patientBillwise

Version:
1.00

MD5:
b534c1a7c9823f23309913c526a6aea9

SHA-1:
6dcaca293ffb97b88cacbacdb047c9a81ef599ce

SHA-256:
4342525f73edf32d6a4f8fc6c38e4d7c2f89311bd0a9598aff310c559eaa1706

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/26/2024 6:36:56 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Patched.Ren.Gen
3.6.1.96

avast!
Win32:WrongInf-A [Susp]
2014.9-150401

NANO AntiVirus
Virus.Win32.Virut-Gen.bwpxnc
0.30.8.659

File size:
576 KB (589,824 bytes)

Product version:
1.00

Original file name:
OPCreditBillHistory.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\bts\hms\opcreditbillhistory.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:Guddwdy4CwQbUFajFOK15yRh/E2gBCAtN7C:3dd4rvQbUFajkK15yRGN+

Entry address:
0x1480

Entry point:
68, F4, 17, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 5B, 67, B3, 86, 76, D0, B2, 49, 9C, 1B, 33, 48, 51, 05, BE, B1, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 57, 65, 69, 67, 70, 61, 74, 69, 65, 6E, 74, 62, 69, 6C, 6C, 77, 69, 73, 65, 00, 00, 00, 00, 00, FF, CC, 31, 00, 07, 4D, DF, 9C, 98, AD, C0, 44, 48, B6, B0, FB, 88, D6, 84, 62, 8D, 7A, CA, C1, 79, EC, DC, E9, 4C, 86, E6, A5, AA, 82, BB, ED, 41, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
0.4738

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
28 KB (28,672 bytes)

Remove OPCreditBillHistory.EXE - Powered by Reason Core Security