systemline.exe

QUANTO SOLUCOES E SISTEMA LTDA

The executable systemline.exe has been detected as malware by 15 anti-virus scanners.
Publisher:
QUANTO SOLUCOES E SISTEMA LTDA  (signed and verified)

MD5:
efe4927bf9c5a91abaeaebc4ca818183

SHA-1:
0509ab84dd57d754f05e06e7a103a73e04676ab7

SHA-256:
9f08ab0618fc5e3a91484530df3ab4cd0f5a06e706f07e6b7f5020758b391826

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/26/2024 1:39:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.518033
107

Arcabit
Trojan.Kazy.D7E791
1.0.0.585

avast!
Win32:Banker-KYB [Trj]
2014.9-161019

Bitdefender
Gen:Variant.Kazy.518033
1.0.20.1465

Bkav FE
HW32.Packed
1.3.0.7383

G Data
Gen:Variant.Kazy.518033
16.10.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.9.5.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.-578

McAfee
Artemis!EFE4927BF9C5
5600.6241

MicroWorld eScan
Gen:Variant.Kazy.518033
17.0.0.879

NANO AntiVirus
Virus.Win32.Gen-Crypt.ccnc
0.30.26.3947

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1015

Trend Micro House Call
TROJ_BANLOAD.YAA
7.2.293

Trend Micro
TROJ_BANLOAD.YAA
10.465.19

VIPRE Antivirus
Trojan.Win32.Generic
44840

File size:
961.3 KB (984,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\systemline.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/2/2014 9:00:00 PM

Valid to:
4/3/2015 8:59:59 PM

Subject:
CN=QUANTO SOLUCOES E SISTEMA LTDA, O=QUANTO SOLUCOES E SISTEMA LTDA, L=PRESIDENTE PRUDENTE, S=SAO PAULO, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
00B87EDE3281FFB1EE77DF86B54A8CB0

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:V4kVqDT/+afAkKDrxb+r9KHF/UndNNGH80EnhmjxeV9i52NeVEfACw12DLp3kCt5:6tHfAkKDNbEQG0Eh+0S5KeVEbwovPh

Entry address:
0xF22C0

Entry point:
F7, D8, EB, 04, 8E, B4, 73, D6, 60, F2, 0F, BB, C9, 8A, F1, B8, 22, 78, 01, 00, E8, 01, 00, 00, 00, C3, 5F, 0F, C0, EB, 69, D7, E6, AF, 3A, B9, 68, A2, AA, 89, 6D, 5F, 0F, B6, F3, 0F, AF, CB, BA, 87, 00, 00, 00, 86, FD, 46, 85, C2, FE, C1, 68, 46, CE, 90, 9D, 0F, BB, DB, 89, F1, 5B, 0F, BC, EE, 89, D9, 84, EF, E8, 02, 00, 00, 00, B6, AE, 59, C7, C5, 83, 81, 37, FF, 45, 0F, A4, C5, 43, 81, ED, 67, 40, F3, 30, 51, F2, 5E, FF, C5, F6, D1, EB, 09, A1, C8, 33, 4C, D7, F1, 41, CC, D0, EB, 09, 08, F1, 21, FA, 39...
 
[+]

Code size:
616 KB (630,784 bytes)

Remove systemline.exe - Powered by Reason Core Security