win2003.exe

WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA

The executable win2003.exe has been detected as malware by 17 anti-virus scanners.
Publisher:
Lobys Yearth Corporation.  (signed by WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA)

Description:
Seth Back Change

Version:
2.0.0.3

MD5:
8205112b2459219e06d7877540c9b98c

SHA-1:
404690deafed8cc77bd61eead4e63731f28f4c2c

SHA-256:
56526a65d6108b8689124ed1690e78232bd872ebb8e34f203c9f5fee86e9aa02

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
4/26/2024 4:35:33 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
TrojanSpy.Banker
7.1.1

Avira AntiVirus
TR/Spy.Bancos.AKZ
7.11.214.38

avast!
Win32:Agent-AUAS [Trj]
2014.9-160520

AVG
Win32/Blacked
2017.0.2737

Comodo Security
UnclassifiedMalware
21311

ESET NOD32
Win32/Spy.Banker.AAQO (variant)
10.11277

Fortinet FortiGate
W32/Banker.AAQO!tr.spy
5/20/2016

F-Prot
W32/Threat-HLLIE-based
v6.4.7.1.166

IKARUS anti.virus
Trojan-PWS.Banker6
t3scan.1.8.6.0

McAfee
Artemis!8205112B2459
5600.6393

Microsoft Security Essentials
TrojanSpy:Win32/Bancos.AKZ
1.1.11400.0

NANO AntiVirus
Trojan.Win32.Bancos.devbgh
0.30.0.296

Norman
Troj_Generic.TFAWV
11.20160520

Panda Antivirus
Trj/Genetic.gen
16.05.20.12

Qihoo 360 Security
Win32/Trojan.7c1
1.0.0.1015

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
38168

File size:
3.1 MB (3,267,680 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\appdata\local\win2003.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/5/2014 9:00:00 PM

Valid to:
3/6/2015 8:59:59 PM

Subject:
CN=WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA, O=WEBPIC DESENVOLVIMENTO DE SOFTWARE LTDA, STREET="RUA RUBIAO JUNIOR, 2386", STREET=PISO SUPERIOR, STREET=PARQUE INDUSTRIAL, L=SAO JOSE DO RIO PRETO, S=SAO PAULO, PostalCode=15025080, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0B0D17EC1449B4B2D38FCB0F20FBCD3A

File PE Metadata
Compilation timestamp:
3/6/2014 12:16:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:jKqHiIo5/tYP6P/YAreUWBT57PSPx79fqVV:jrCnrYPR557o/fG

Entry address:
0x526BC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 80, C4, 84, 00, B0, 7C, 8D, D3, FE, 91, 35, 3C, 6E, 20, C5, CE, 9D, AA, E4, C9, 19, DF, E1, 3F, A5, 9B, F4, 3B, EB, 6C, EF, 93, 11, B8, 96, A2, 93, 18, D5, 1E, 5C, 56, 3E, 05, 03, 52, 0D, E7, ED, 13, D6, DC, 13, 8D, 25, C0, 9D, D3, AC, 2B, 97, A6, 25, 77, 33, D6, 6F, 67, FE, 9C, 50, 44, 17, 79, 37, DB, 52, 7F, 15, F7, 6B, 61, EB, 12, B1, C8, 66, E3, 9F, 70, D2, DE, C2, 50, 46, 0B, F3, 7C, F1, E1, 28, 62, F3, 46...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.9 MB (4,134,912 bytes)

Remove win2003.exe - Powered by Reason Core Security