afcassistente.exe

AFC Assistente

AFC Software

This is a setup program which is used to install the application. The file has been seen being downloaded from afcsoftware.net.
Publisher:
AFC Software

Product:
AFC Assistente

Description:
AFC Assistente - Assistente Virtual

Version:
2.04.0006

MD5:
facf9ae3bc6b5c0329eb6b027063e3bf

SHA-1:
0ed521e58f6a6937afadfd7dfe1865036461c18b

SHA-256:
7494f0061d9692fd71b5f82f049910caa2e5e331323448cd5c6ca6cc521689ba

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/27/2024 7:49:13 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.VB
2014.09.17

avast!
Win32:Dropper-gen [Drp]
2014.9-150925

ESET NOD32
probably unknown NewHeur_PE
9.10430

File size:
5.8 MB (6,070,272 bytes)

Product version:
2.04.0006

Original file name:
afc.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\afc assistente\afcassistente.exe

File PE Metadata
Compilation timestamp:
6/21/2014 10:41:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:zio2N8jyWEmlL9XBi30GM58LgPjI2QGYKlmJ39ElEnjnXRAGbAt28It5ffrxMoi:/kWEaXH5sgPjI2QGYHJNESA3c8It5ff2

Entry address:
0x4AF4

Entry point:
68, 50, AE, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, B3, A2, E3, B7, E4, 68, 75, 40, 8C, 2C, 56, 3C, CB, 19, A5, B9, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 41, 46, 43, 41, 73, 73, 69, 73, 74, 65, 6E, 74, 65, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 0C, 51, F0, 38, EF, 66, 1D, 6B, 42, 8E, 28, 7B, 71, 3E, A2, 87, 5A, 0A, D9, E6, 12, C6, F0, B5, 4B, A6, D9, BF, 2F, EC, 49, E3, E2, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
5.7 MB (5,951,488 bytes)

The file afcassistente.exe has been seen being distributed by the following URL.

Scan afcassistente.exe - Powered by Reason Core Security