comprovante anexo-fiscal7682322016.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from ws.cubbyusercontent.com.
MD5:
1433c1b7487dbb8dd8d2d5a30833e749

SHA-1:
b8bfb355584d2b3c98ad33d3b101ea5952e275f1

SHA-256:
8e140fb58bf4611c4a23180c914925d515944f83622cd1351aa91b01efc08755

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 7:51:56 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/TrojanDownloader.Banload.XFM trojan
8.0.319.0

Qihoo 360 Security
QVM05.1.Malware.Gen
1.0.0.1120

File size:
1 MB (1,054,208 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\comprovante anexo-fiscal7682322016.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:douFXXcTJRc7xWNiwHQqnvjfN1m5YHBEwTRqG755TX6Ad2h9pVlXGZLirs7FW:KE8TLc7xW6q7F+YHBr1l1Dd2hbDyL7

Entry address:
0xB16E4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 6C, 12, 4B, 00, E8, 88, 4B, F5, FF, 8B, 0D, 58, AB, 4B, 00, A1, 74, A9, 4B, 00, 8B, 00, 8B, 15, 04, 0C, 4B, 00, E8, 50, 35, FA, FF, 8B, 0D, B8, AB, 4B, 00, A1, 74, A9, 4B, 00, 8B, 00, 8B, 15, F8, 08, 4B, 00, E8, 38, 35, FA, FF, A1, 74, A9, 4B, 00, 8B, 00, E8, AC, 35, FA, FF, E8, 0B, 29, F5, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
706 KB (722,944 bytes)

The file comprovante anexo-fiscal7682322016.exe has been seen being distributed by the following URL.

Scan comprovante anexo-fiscal7682322016.exe - Powered by Reason Core Security