arquivo.exe

BR SOFTWARE LLC

The application arquivo.exe by BR SOFTWARE has been detected as adware by 39 anti-malware scanners. This is a setup program which is used to install the application. This setup program installs potentially unwanted software on the user's PC at the same time as the expected/marketing software, without adequate consent. The program is typically installed via a form of malvertising The file has been seen being downloaded from www.onlinemidia.com and multiple other hosts.
Publisher:
BR SOFTWARE LLC  (signed and verified)

Version:
1.0.0.0

MD5:
5a007864b1ec75c23203fc73a35bb7c4

SHA-1:
e9292d5df36e2bdd0d7de5b3a23983ce22042502

SHA-256:
9e1f441187cd406c33be057d9594185ee1ce9f8c3ce442a2166b3ba01a573361

Scanner detections:
39 / 68

Status:
Adware

Analysis date:
11/5/2024 9:55:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8543522
871

Agnitum Outpost
Trojan.Foreign
7.1.1

Avira AntiVirus
Adware/PCMega.S
7.11.149.24

avast!
Win32:Downloader-SCT [Adw]
2014.9-140917

AVG
AdInstaller.O
2015.0.3349

Baidu Antivirus
Adware.MSIL.PCMega
4.0.3.14917

Bitdefender
Trojan.Generic.8543522
1.0.20.1300

Comodo Security
UnclassifiedMalware
18258

Dr.Web
Trojan.DownLoader7.49131
9.0.1.0260

Emsisoft Anti-Malware
Trojan.Generic.8543522
8.14.09.17.12

ESET NOD32
MSIL/Adware.PCMega (variant)
8.9786

Fortinet FortiGate
Adware/Fam.NB
9/17/2014

F-Secure
Trojan.Generic.8543522
11.2014-17-09_4

G Data
Trojan.Generic.8543522
14.9.24

IKARUS anti.virus
SoftwareBundler
t3scan.1.6.1.0

K7 AntiVirus
Backdoor
13.177.12041

Malwarebytes
Trojan.Arqudrop
v2014.09.17.12

McAfee
Artemis!5A007864B1EC
5600.7005

Microsoft Security Essentials
SoftwareBundler:MSIL/Protlerdob
1.10502

MicroWorld eScan
Trojan.Generic.8543522
15.0.0.780

NANO AntiVirus
Trojan.Win32.Agent.beoqkb
0.28.0.59608

nProtect
Trojan.Generic.8543522
14.05.11.01

Panda Antivirus
Trj/Agent.MIZ
14.09.17.12

Qihoo 360 Security
Win32/Trojan.Adware.2f9
1.0.0.1015

Reason Heuristics
PUP.BRSOFTWARE.H
14.9.17.0

Sophos
Generic PUA OJ
4.98

Trend Micro House Call
ADW_PCMEGA
7.2.260

Trend Micro
ADW_PCMEGA
10.465.17

Vba32 AntiVirus
Trojan.MSIL
3.12.26.0

VIPRE Antivirus
MSIL.Adware.PCMega
29118

Zillya! Antivirus
Adware.PCMega.Win32.36
2.0.0.1785

File size:
19 KB (19,448 bytes)

Product version:
1.0.0.0

Original file name:
f281212.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\arquivo.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/28/2012 8:19:23 PM

Valid to:
4/17/2013 4:03:06 PM

Subject:
CN=BR SOFTWARE LLC, O=BR SOFTWARE LLC, L=Lewes, S=DE, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0406DFFBFD30F8

File PE Metadata
Compilation timestamp:
12/30/2012 9:10:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:oV509UPT6QRs89FnwTkpIT3F/CTP3wo+bOokVQNX+NeTL3TNeT4+vDtIjEKdm0od:oY9mg83wTGa/CYoeH+NeLNek+vDn50W

Entry address:
0x459E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 60, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
9.5 KB (9,728 bytes)

The file arquivo.exe has been seen being distributed by the following 2 URLs.

http://www.onlinemidia.com/ids/.../Chico Buarque – Na Carreira: Ao Vivo (2012).zip

Remove arquivo.exe - Powered by Reason Core Security