trzc04c.tmp

SAPO

The file trzc04c.tmp has been detected as malware by 1 anti-virus scanner.
Publisher:
SAPO  (signed and verified)

Version:
1.0.0.0

MD5:
a5e9e7bda40f1f56345477a1dabc7204

SHA-1:
f415818d9437dd4b700a2c17dbea413df2219ecb

SHA-256:
f8a31ef38e7034cf905976b6d6362bd511bdafa49b356121911efc1ceb6b5547

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/5/2024 11:34:17 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Downloader (M)
16.3.9.12

File size:
10.9 MB (11,451,512 bytes)

Product version:
1.0.0.0

Language:
Maltês (Malta)

Common path:
C:\users\{user}\appdata\roaming\trzc04c.tmp

Digital Signature
Signed by:

Authority:
SAPO

Valid from:
6/5/2015 2:08:35 PM

Valid to:
6/5/2016 2:08:35 PM

Subject:
E=cmd@sapo.pt, CN=SAPO.PT, OU=SAPO Division of Protocol, O=SAPO, L=Opalo, S=Jobila, C=AS

Issuer:
E=cmd@sapo.pt, CN=SAPO.PT, OU=SAPO Division of Protocol, O=SAPO, L=Opalo, S=Jobila, C=AS

Serial number:
00A7AB2CD21ECC7345

File PE Metadata
Compilation timestamp:
6/10/2015 6:49:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:XF00zGQyxV7cQ3LH+L5Q4F+kQvPsIpH7lcJKDpmXazIq868rrWTUB4Go:XF0+GQaQ+r+LO4F+kCsIZ7lWKDQKz18e

Entry address:
0xDBD690

Entry point:
51, 9C, E8, D7, 04, AC, 00, 9C, B7, AF, C4, E9, B5, 68, CA, 33, B3, 7C, 38, CB, 13, 0B, F1, 7A, 1C, DD, 69, 7B, 7C, B1, 4E, 9B, 32, B9, 30, 37, 51, 1A, 36, 34, 23, 46, 18, 50, 1C, 0E, 3F, EB, 7C, 18, 12, FB, 6E, C1, 91, EC, E6, EE, F8, 32, AB, 20, C9, 91, 21, F5, D9, B9, 07, BD, B6, F9, 89, A3, B4, 6A, 77, 9E, C7, 4C, 41, EB, F4, EB, 86, 29, 86, 03, 28, FC, AE, FD, F8, A6, 9C, 8E, E7, 62, 26, FA, E0, 6C, 37, 26, 8C, 4A, 90, 94, 17, 99, 51, 36, D5, 9A, 4D, AE, DE, 6A, DF, E9, FC, 0E, 5A, 84, 35, 9B, 62, A7...
 
[+]

Code size:
3.1 MB (3,236,864 bytes)

Remove trzc04c.tmp - Powered by Reason Core Security