gerador pin pbbr.exe

Sistem32

The executable gerador pin pbbr.exe has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc231.4shared.com.
Publisher:
Microsoft*  (Invalid match)

Product:
Sistem32

Version:
1.0.0.0

MD5:
dd6d36af9b7605bf9a7878b292c3cfdd

SHA-1:
d6fc6752a40538f3a24699aa7c12f282084d628c

SHA-256:
f8e38e8d0d27bdf07ecbe5edc50070fd4ee63d56ef9be70759521b8ab0d51e65

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
11/24/2024 3:41:49 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.712254
252

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Dropper.Gen
8.3.2.2

Arcabit
Trojan.Kazy.DADE3E
1.0.0.527

avast!
Win32:Malware-gen
2014.9-160527

Baidu Antivirus
Hacktool.MSIL.Confuser
4.0.3.16527

Bitdefender
Gen:Variant.Kazy.712254
1.0.20.740

Emsisoft Anti-Malware
Gen:Variant.Kazy.712254
8.16.05.27.01

ESET NOD32
MSIL/Packed.Confuser.P suspicious (variant)
10.12250

F-Prot
W32/MSIL_Troj.DL.gen
v6.4.7.1.166

G Data
Gen:Variant.Kazy.712254
16.5.25

IKARUS anti.virus
Trojan.MSIL.Crypt
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.210.17205

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.147

MicroWorld eScan
Gen:Variant.Kazy.712254
17.0.0.444

VIPRE Antivirus
Trojan.Win32.Generic
43742

File size:
187.3 KB (191,776 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2015

Original file name:
Sistem32.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\gerador pin pbbr.exe

File PE Metadata
Compilation timestamp:
9/6/2015 2:56:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:rtreQudBAF/x5ZE4PxYMf2+IcMKjAIBlC0wH45BkhqzvtjwfwoLi2boX1UR1L:r4QujR4Cq0cD8GC0YekhGGTomt

Entry address:
0x29B5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
159 KB (162,816 bytes)

The file gerador pin pbbr.exe has been seen being distributed by the following URL.

Remove gerador pin pbbr.exe - Powered by Reason Core Security