installer.exe

SOFTWARE CENTER INFORMATICA LTDA - ME

The executable installer.exe has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
SOFTWARE CENTER INFORMATICA LTDA - ME  (signed and verified)

MD5:
c5713b275979be830ddb0b600d7d8b6f

SHA-1:
6e156ab9870787ac0bda6dac321b6b3c92dcb3b6

SHA-256:
04e1dc1ff0e18b8d9a7113dd6889005bd8d9b9981e6ecf0876b497a9cb5c1619

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/23/2024 10:58:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.8.5.4

File size:
8.5 MB (8,869,728 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\installer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/24/2015 2:34:16 PM

Valid to:
4/24/2016 2:34:16 PM

Subject:
CN=SOFTWARE CENTER INFORMATICA LTDA - ME, OU=TI, O=SOFTWARE CENTER INFORMATICA LTDA - ME, L=JUQUITIBA, S=SAO PAULO, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E4364E01A7278CB5E2EEB812C5E418BA

File PE Metadata
Compilation timestamp:
5/18/2015 11:18:27 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.24

CTPH (ssdeep):
196608:rd+AMa8S/cxXaZ9UrdLKxDGQaNVyI0tRoE:rcY1cFhQaqI0tGE

Entry address:
0xEC5718

Entry point:
9C, 60, E8, 21, 68, 86, 00, E9, 44, 69, 0A, 00, CE, 73, 63, A2, 49, 8A, F1, 29, FF, D6, 8D, 8E, 8D, A6, 33, C4, 12, 76, E0, 1A, BA, AB, 46, 70, E5, D1, 83, D0, 89, F8, 73, 4E, 8B, CF, 09, A6, C7, A9, 4F, 92, 3C, F0, 11, 48, 37, 4D, 25, AB, B4, 15, BB, AF, 80, 4C, 07, 72, 39, 8B, A7, DE, E2, 8D, B2, 4C, 7D, 4F, 25, 90, 4A, 62, F8, 74, 08, 22, 31, 6C, 2B, E9, 7A, 01, BB, C1, 8A, C2, F9, 82, B8, BA, 1C, 87, 5F, 8F, EF, BF, AB, 2F, 57, D8, 22, 33, 99, 92, 0D, 61, 52, 82, 7B, 8C, 5A, 80, 70, 6A, 86, 48, 00, F4...
 
[+]

Code size:
27.5 KB (28,160 bytes)

Remove installer.exe - Powered by Reason Core Security