b6c6425d.exe

SOFTWARE CENTER INFORMATICA LTDA - ME

The executable b6c6425d.exe has been detected as malware by 1 anti-virus scanner. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
SOFTWARE CENTER INFORMATICA LTDA - ME  (signed and verified)

MD5:
2ac7e8d92cf55f73f21d60368f514d8d

SHA-1:
a25f721f36cb7a797e30d7dae46e646abe927a74

SHA-256:
5a527a43f663c58b2d2f59ee51ab3d5b8f385c0ac1de15f09899fd2b5d779c26

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
2/25/2025 12:25:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.20.18

File size:
692.3 KB (708,960 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\b31b0bfc\b6c6425d.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/24/2015 2:34:16 PM

Valid to:
4/24/2016 2:34:16 PM

Subject:
CN=SOFTWARE CENTER INFORMATICA LTDA - ME, OU=TI, O=SOFTWARE CENTER INFORMATICA LTDA - ME, L=JUQUITIBA, S=SAO PAULO, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E4364E01A7278CB5E2EEB812C5E418BA

File PE Metadata
Compilation timestamp:
5/18/2015 2:48:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.24

CTPH (ssdeep):
12288:mabP96bt36lv47QsrskBZhBAMO4WVmhlxOqvsm0LPaki+Kh2wate3:maz9nd47prsiAMrW4/xjwrakI2wD3

Entry address:
0x143F8C

Entry point:
60, 68, AF, 63, B1, 09, 9C, FF, 74, 24, 10, C7, 44, 24, 28, 7B, B6, 4D, 47, E9, 56, 85, 00, 00, BE, 4B, E0, 63, 04, AF, 2A, A3, 75, EA, 44, D3, B3, AA, 84, 0D, 8E, E9, 8E, A9, DE, 79, FE, 69, F6, 91, EE, 71, E2, 6D, 06, 69, CA, B5, 36, 01, 76, C1, 60, B6, 25, A8, 75, E4, 67, 04, A9, 87, 2F, 6B, 23, A3, CC, B1, 43, 02, 65, 4A, 8F, 8A, 0B, AA, 6B, 00, AD, 38, 99, 29, 36, 5C, 05, 48, 2D, CE, B1, BB, 1A, D9, 97, E2, 5B, 1D, B4, 39, 05, 70, F3, B0, 41, 77, CA, DD, AD, BD, 38, 99, 2C, 14, 3D, AD, BE, 0E, 33, 1C...
 
[+]

Code size:
18 KB (18,432 bytes)

Scheduled Task
Task name:
{A3F15C50-F587-48B7-F24E-D43706583D3A}

Trigger:
Logon (Runs on logon)


Remove b6c6425d.exe - Powered by Reason Core Security