pendencias.exe

WindowsFormsApplication1

LUYARA FELIX DE ARAUJO 05168873359

The application pendencias.exe by LUYARA FELIX DE ARAUJO 05168873359 has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from vivoempresacorporativobh.com.br.
Publisher:
LUYARA FELIX DE ARAUJO 05168873359  (signed and verified)

Product:
WindowsFormsApplication1

Version:
1.0.0.0

MD5:
b36f9dc3fe7bb667d5567f84b21903b0

SHA-1:
0e63b06cf1ddc22bc2f6593b63a0e88248592a37

SHA-256:
a815d252920ffd6caeee313d78879b8f3de7093dbb81dc4e3cf9caacf237ecfc

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
5/16/2025 1:50:13 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14615792
331

AhnLab V3 Security
Trojan/Win32.Dynamer
2015.10.14

Avira AntiVirus
TR/Spy.Banker.80904
8.3.2.2

avast!
Win32:Banker-LTF [Trj]
2014.9-160310

AVG
MSIL8
2017.0.2809

Baidu Antivirus
Trojan.MSIL.Banker
4.0.3.16310

Bitdefender
Trojan.Generic.14615792
1.0.20.350

Emsisoft Anti-Malware
Trojan.Generic.14615792
8.16.03.10.08

ESET NOD32
MSIL/Spy.Banker.CN (variant)
10.12402

F-Secure
Trojan.Generic.14615792
11.2016-10-03_5

G Data
Trojan.Generic.14615792
16.3.25

K7 AntiVirus
Unwanted-Program
13.210.17525

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.538

McAfee
Downloader-FAVK!B36F9DC3FE7B
5600.6465

MicroWorld eScan
Trojan.Generic.14615792
17.0.0.210

nProtect
Trojan.Generic.14615792
15.10.13.01

Panda Antivirus
Trj/CI.A
16.03.10.08

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R02SC0OFI15
10.465.10

File size:
79 KB (80,904 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
lasssttt.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pendencias.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/10/2014 1:19:06 PM

Valid to:
11/11/2015 1:19:06 PM

Subject:
CN=LUYARA FELIX DE ARAUJO 05168873359, OU=TI, O=LUYARA FELIX DE ARAUJO 05168873359, L=Imperatriz, S=Maranhao, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D20CD8AF8CA0767E911EE22F03281F76

File PE Metadata
Compilation timestamp:
4/23/2015 3:19:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:4oekSY0b9r981t/7iSkRwmOYfjBA9gJQHw3gsowW0djoLLfEUJgIa:TekSY0b9rGb4wmAuJQHogsowW0loLLfg

Entry address:
0x42CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
9 KB (9,216 bytes)

The file pendencias.exe has been seen being distributed by the following URL.

Remove pendencias.exe - Powered by Reason Core Security