49.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.validcertificadora.com.br.
MD5:
7ecc412109d3ea435bd1ba470eff2071

SHA-1:
9019ad610bc43b1c300a475cc7d11f93d7873c60

SHA-256:
19c50d0b2bebd4e7a2335be5f0a100acb20fd7843bd71ae94adcbc20de79cbda

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:32:45 AM UTC  (today)

File size:
81.3 KB (83,289 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\49.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
1536:G/w3qYNNnPQpmjelfjr2qMqXGkrveXt7E0oJM+Zm21QZnIX5IbbmtvaTiLf1ylQO:G/waYNmp8ehQqXGkrveXt7E0uM+82qZP

Entry point:
0D, 0A, 0D, 0A, 3C, 21, 44, 4F, 43, 54, 59, 50, 45, 20, 68, 74, 6D, 6C, 20, 50, 55, 42, 4C, 49, 43, 20, 22, 2D, 2F, 2F, 57, 33, 43, 2F, 2F, 44, 54, 44, 20, 58, 48, 54, 4D, 4C, 20, 31, 2E, 30, 20, 54, 72, 61, 6E, 73, 69, 74, 69, 6F, 6E, 61, 6C, 2F, 2F, 45, 4E, 22, 20, 22, 68, 74, 74, 70, 3A, 2F, 2F, 77, 77, 77, 2E, 77, 33, 2E, 6F, 72, 67, 2F, 54, 52, 2F, 78, 68, 74, 6D, 6C, 31, 2F, 44, 54, 44, 2F, 78, 68, 74, 6D, 6C, 31, 2D, 74, 72, 61, 6E, 73, 69, 74, 69, 6F, 6E, 61, 6C, 2E, 64, 74, 64, 22, 3E, 0D, 0A, 3C...
 
[+]

The file 49.exe has been seen being distributed by the following URL.

Scan 49.exe - Powered by Reason Core Security