18865f7b.dll

SOFTWARE CENTER INFORMATICA LTDA - ME

The library 18865f7b.dll has been detected as malware by 1 anti-virus scanner.
Publisher:
SOFTWARE CENTER INFORMATICA LTDA - ME  (signed and verified)

MD5:
f788edc0505d10ee033c1fd61cd98935

SHA-1:
d85042a562ec0330a683cea47add6729d7c38d45

SHA-256:
fb7edd6d97f64c010c8db892e4994fa55642f6b5b18de04324f34ca220dbb9c2

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/23/2024 10:47:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.27.9

File size:
168.8 KB (172,896 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\ProgramData\cb5793af\18865f7b.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/24/2015 2:34:16 PM

Valid to:
4/24/2016 2:34:16 PM

Subject:
CN=SOFTWARE CENTER INFORMATICA LTDA - ME, OU=TI, O=SOFTWARE CENTER INFORMATICA LTDA - ME, L=JUQUITIBA, S=SAO PAULO, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E4364E01A7278CB5E2EEB812C5E418BA

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
1536:3GAd0L9uQfpmsV29PrOTiLUsMMGLtehb1zvqR0jqWlHNbrUg9XyFkVhEc:hkuo4yip0Yb1O0jqGZrUgV33

Entry address:
0x1420

Entry point:
83, EC, 1C, 8B, 54, 24, 24, C7, 05, 34, 77, 4E, 61, 00, 00, 00, 00, 83, FA, 01, 74, 1A, 8B, 4C, 24, 28, 8B, 44, 24, 20, E8, 1D, FE, FF, FF, 83, C4, 1C, C2, 0C, 00, 8D, B4, 26, 00, 00, 00, 00, 89, 54, 24, 0C, E8, C7, FE, 00, 00, 8B, 54, 24, 0C, EB, D7, 90, 55, 89, E5, 56, 53, 83, EC, 10, 8B, 1D, A0, 92, 4E, 61, C7, 04, 24, 00, D0, 4D, 61, FF, D3, 89, C6, 83, EC, 04, B8, E0, 5A, 4D, 61, 85, F6, 74, 29, C7, 04, 24, 00, D0, 4D, 61, FF, 15, D4, 92, 4E, 61, 83, EC, 04, A3, 04, 7B, 4E, 61, C7, 44, 24, 04, 13, D0...
 
[+]

Code size:
92 KB (94,208 bytes)

Remove 18865f7b.dll - Powered by Reason Core Security