votorantim_350277909848838-ip800.pdf.exe

CurrentVersion

The executable votorantim_350277909848838-ip800.pdf.exe has been detected as malware by 24 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from storage.googleapis.com.
Product:
CurrentVersion

Version:
1.00

MD5:
b4ffa2f1ded1c8ce26694ad17603e215

SHA-1:
f37b830ce51b8de544987e8ea4406afef77ab1ee

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/25/2024 8:49:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2017823
676

Agnitum Outpost
Trojan.DL.Banload
7.1.1

AhnLab V3 Security
Trojan/Win32.Injector
2015.02.03

Avira AntiVirus
TR/Dropper.VB.24877
7.11.206.130

Baidu Antivirus
Trojan.Win32.VB
4.0.3.15330

Bitdefender
Trojan.GenericKD.2017823
1.0.20.445

Emsisoft Anti-Malware
Trojan.GenericKD.2017823
8.15.03.30.03

ESET NOD32
Win32/TrojanDownloader.Banload.ULZ
9.11110

Fortinet FortiGate
W32/Banker.EKCJ!tr
3/30/2015

G Data
Trojan.GenericKD.2017823
15.3.25

IKARUS anti.virus
Trojan-Downloader.Win32.Banload
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.193.14832

Kaspersky
Trojan-Downloader.Win32.VB
14.0.0.2267

Malwarebytes
Trojan.Downloader
v2015.03.30.03

McAfee
RDN/PWS-Banker.dldr!i
5600.6810

MicroWorld eScan
Trojan.GenericKD.2017823
16.0.0.267

NANO AntiVirus
Trojan.Win32.VbCrypt.djzonp
0.30.0.65070

Norman
Suspicious_Gen4.HIXTP
11.20150330

nProtect
Trojan.GenericKD.2017823
15.01.30.01

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Quick Heal
TrojanDownloader.Broban.r3
3.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.17EC2F4E!401354574
23.00.65.15328

Sophos
Troj/Banker-GGV
4.98

ViRobot
Trojan.Win32.S.Agent.472126[h]
2014.3.20.0

File size:
461.1 KB (472,126 bytes)

Product version:
1.00

Original file name:
gABA.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\documents and settings\apoio.baratela2\meus documentos\downloads\votorantim_350277909848838-ip800.pdf.exe

File PE Metadata
Compilation timestamp:
12/5/2014 9:37:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:rRnjxyB8AFO2hylsXhY/zDtpZ4pPKqAxxe3M6NgXuN9P:rRnjxPAFGlMOrzZEPKqKxxp+Nt

Entry address:
0x1578

Entry point:
68, 80, 17, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, F0, 25, C0, EE, F3, 63, 31, 4E, A4, FA, 65, A6, A6, 41, 36, DA, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 43, 75, 72, 72, 65, 6E, 74, 56, 65, 72, 73, 69, 6F, 6E, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 00, EB, 91, 80, 8D, BC, B7, FC, 41, 93, 4B, 66, 59, C5, 9A, 64, C5, E3, 51, C2, B8, 0F, C3, 55, 48, B5, 8B, 96, 31, 02, 59, E2, E2, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
32 KB (32,768 bytes)

The file votorantim_350277909848838-ip800.pdf.exe has been seen being distributed by the following URL.

Remove votorantim_350277909848838-ip800.pdf.exe - Powered by Reason Core Security