IBExpert.exe

IB Expert

HK-Software

This is a setup program which is used to install the application. The file has been seen being downloaded from www.onclicksistemas.net and multiple other hosts.
Publisher:
HK-Software

Product:
IB Expert

Description:
IBExpert - The Most Expert for InterBase and Firebird

Version:
2012.2.21.1

MD5:
aef03cb24e968d1552b8c1192d51e192

SHA-1:
4bd213f9046c43d149daa1d71daea544043a432d

SHA-256:
7200c8657a0590f32ae2634730bc75addc5dc5fef5201fa1b111575feadfaa2d

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/15/2024 11:38:45 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

ViRobot
Trojan.Win32.A.Inject.17254068
2011.4.7.4223

File size:
16.5 MB (17,254,068 bytes)

Product version:
2007.4.29.1

Copyright:
HK-Software

Original file name:
IBExpert.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:vkFxA66tCW6dhB7OO6VbcQTWYQ2ZVLqAKyf4A:8F0tCWOhB56VbNTWYBVLqMfp

Entry address:
0xB9F3F4

Entry point:
55, 8B, EC, B9, 0F, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 24, D3, F9, 00, E8, E0, A3, 46, FF, 33, C0, 55, 68, 1B, FF, F9, 00, 64, FF, 30, 64, 89, 20, A1, 0C, 10, 00, 01, E8, E8, 50, 46, FF, 8D, 55, F0, B8, 1A, 00, 00, 00, E8, 5B, AF, EE, FF, 8B, 55, F0, A1, 0C, 10, 00, 01, E8, 22, 51, 46, FF, A1, 0C, 10, 00, 01, 83, 38, 00, 0F, 85, 81, 00, 00, 00, B2, 01, A1, 90, A0, 46, 00, E8, 50, AE, 4C, FF, A3, 58, 56, 2D, 01, 33, C0, 55, 68, CA, F4, F9, 00, 64, FF, 30, 64, 89, 20, BA, 01, 00, 00, 80...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
11.6 MB (12,186,624 bytes)

The file IBExpert.exe has been seen being distributed by the following 5 URLs.

http://www.onclicksistemas.net/.../ibxp.exe

ftp://ftp.supersoft.com.br:2021/pub/ferramentas/.../ibexpert.exe

Scan IBExpert.exe - Powered by Reason Core Security