playback musica coracao de mae aline barros.exe

BR SOFTWARE LLC

The application playback musica coracao de mae aline barros.exe, “Download da Internet” by BR SOFTWARE has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.wikizu.net.
Publisher:
BR SOFTWARE LLC  (signed and verified)

Description:
Download da Internet

Version:
9.9.9.7

MD5:
ad05a0fe3d9e8b81c0e4b503716ac48a

SHA-1:
f6e01a692fbdafabd84ed6ca4658a86b709631fd

SHA-256:
a4861794cb6d0e5a3021d72da863207d14fa6e46f7030f2b2651d2d6469852a6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/3/2024 7:03:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BR Software (M)
16.7.17.17

File size:
69.5 KB (71,120 bytes)

Copyright:
564p5fVYwUjXMllPF

Trademarks:
564p5fVYwUjXMllPF5v604bSLCW0

Original file name:
564p5fVYwUjXMllP

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\playback musica coracao de mae aline barros.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/25/2015 4:17:38 PM

Valid to:
4/11/2015 3:16:52 PM

Subject:
CN=BR SOFTWARE LLC, O=BR SOFTWARE LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0091451BD3F0C58EE2

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:xQpQ5EP0ijnRTXJNq5sSvC1DDw8UjZn2bMfJSewm+4hBxSDI8FB3:xQIURTXJNq5xC1JUjoIBD+IwXF9

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file playback musica coracao de mae aline barros.exe has been seen being distributed by the following URL.