andemos na luz arautos do rei lanamento 2014.exe

g3CvT78vSMa0N0LPai7QvtmUw

GENCO LABS LLC

The application andemos na luz arautos do rei lanamento 2014.exe by GENCO LABS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from getld.space.
Publisher:
g3CvT78vSMa0N0LPai7QvtmUwmghB  (signed by GENCO LABS LLC)

Product:
g3CvT78vSMa0N0LPai7QvtmUw

Version:
5.9.1.7

MD5:
67b07e3e6a83b2d37aef44fa2c056320

SHA-1:
d7034825deb25a0b6c5fdc8ed64acece1f604154

SHA-256:
a6bd191ab4f19ba3c94f6f7f2c9fdb3416ec82b715f557ba6a6d68ec99003cfb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 5:35:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BR Software (M)
16.7.22.22

File size:
69.4 KB (71,112 bytes)

Trademarks:
g3CvT78vSMa0N0LP

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\andemos na luz arautos do rei lanamento 2014.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
4/2/2015 10:13:39 AM

Valid to:
10/20/2015 7:14:36 PM

Subject:
CN=GENCO LABS LLC, O=GENCO LABS LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00DCC6832CB96E85F8

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:RQpQ5EP0ijnRTXJz54Gc9+BUM/wAcP0lscLD8I:RQIURTXJz54GW+BUM/w9ifz

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file andemos na luz arautos do rei lanamento 2014.exe has been seen being distributed by the following URL.