gerador de itens otpokemon 1.0.exe

Gerador De Itens Otpokemon 1.0 Install Program

The executable gerador de itens otpokemon 1.0.exe has been detected as malware by 4 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from fs10n5.sendspace.com.
Product:
Gerador De Itens Otpokemon 1.0 Install Program

Version:
2,0,0,45

MD5:
cf23d745301a72965ee2fbe054ff0503

SHA-1:
c323252f0c5223b82e1a797a3abfa07b1742ef41

SHA-256:
cb15e3d3927650bf3972f02fd2917811ebffebdb33524e3b58110f395c3709bd

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
11/24/2024 11:08:29 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Parite
160518-2

ESET NOD32
Win32/Parite.B virus
8.0.319.0

F-Prot
W32/Parite.B
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.110.0

File size:
793.5 KB (812,516 bytes)

Product version:
2,0,0,45

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gerador de itens otpokemon 1.0.exe

File PE Metadata
Compilation timestamp:
10/2/2015 12:39:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:PR8SB3TsfFzx5qFJald/fHvduXSFX1kT512oZdh:PRkz/SMPdgS51kN1d

Entry address:
0x23000

Entry point:
90, 90, 68, 2A, 71, 21, 00, 59, 90, 68, 2A, 30, 42, 00, 5F, 90, 68, 98, 05, 00, 00, 5E, 90, 90, FF, 34, 3E, 31, 0C, 24, 8F, 04, 3E, 90, 90, 4E, 83, EE, 03, 90, 90, 75, ED, 90, 90, 90, C2, 0C, 20, 00, 2A, 71, 21, 00, 2A, 71, 61, 00, 16, 31, 20, 00, 57, D6, 28, 00, CE, C4, 28, 00, 2A, C1, 23, 00, 2B, 71, 21, 00, 8E, F1, 60, 00, 6A, E3, 60, 00, 7C, E3, 60, 00, C2, FD, 20, 00, 14, E3, 20, 00, 7E, E3, 20, 00, 8E, F1, 20, 00, 14, E3, 20, 00, 7E, E3, 20, 00, 2A, 71, 21, 00, 2A, 71, 21, 00, 2A, 71, 21, 00, 4A, F0...
 
[+]

Code size:
92 KB (94,208 bytes)

The file gerador de itens otpokemon 1.0.exe has been seen being distributed by the following URL.

Remove gerador de itens otpokemon 1.0.exe - Powered by Reason Core Security