instaladorcadeiav2.exe

CertiSignerChain

Certisign

This is a setup program which is used to install the application. The file has been seen being downloaded from www.fenaconcd.com.br and multiple other hosts.
Publisher:
Certisign

Product:
CertiSignerChain

Description:
Instalador de cadeias Certisign

Version:
1.2.0.2

MD5:
0322ab9d20fb61301f7ec4d892872cea

SHA-1:
a8846aebec27bae0af16c9ea92bb6af7c0efa22b

SHA-256:
981457ed3a19f4f0c6df0e10fe9b4f925932f5161b154c07b73291578673a83d

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 2:02:05 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

Zillya! Antivirus
Adware.BrowseFox.Win32.185201
2.0.0.2565

File size:
1.5 MB (1,534,976 bytes)

Product version:
1.2.0.2

Copyright:
(c) 2015 Certisign Certificadora Digital S.A.

Original file name:
CertiCha.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\instaladorcadeiav2.exe

File PE Metadata
Compilation timestamp:
11/10/2015 5:44:45 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:eYxFQSSe+KpPb/GjGVL2cRDwLwYOwEpJFJzmf4CT:eIFrTrNRDifEpJFJzRCT

Entry address:
0xDFA57

Entry point:
E8, AB, E0, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, D4, 55, 00, E8, D3, CB, 00, 00, E8, BE, 90, 00, 00, 0F, B7, F0, 6A, 02, E8, 3E, E0, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 81, C2, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
1 MB (1,091,072 bytes)

The file instaladorcadeiav2.exe has been seen being distributed by the following 2 URLs.

Scan instaladorcadeiav2.exe - Powered by Reason Core Security