intimacao-mpf.exe

The executable intimacao-mpf.exe has been detected as malware by 32 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from sao01.objectstorage.softlayer.net.
MD5:
ebd116628a340250a65b08b0764b02e4

SHA-1:
d45fa2b939e6db97851fff8cb050e4c5efc192c4

SHA-256:
7f856d6997ab1c30a599732b3b5fff53fe00e2cbc14e8fa880adb6a29077a43e

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
11/28/2024 3:20:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2779864
316

AegisLab AV Signature
Troj.Downloader.W32.Agent.hgdx!c
2.1.4+

AhnLab V3 Security
Trojan/Win32.Ba
2016.02.17

Avira AntiVirus
TR/VB.Agent.519680
8.3.3.2

Arcabit
Trojan.Generic.D2A6AD8
1.0.0.653

avast!
VBS:Banker-BT [Trj]
2014.9-160324

AVG
Collected_c
2017.0.2794

Baidu Antivirus
Trojan.VBS.Agent
4.0.3.16324

Bitdefender
Trojan.GenericKD.2779864
1.0.20.420

Comodo Security
TrojWare.Win32.TrojanDownloader.Agent.WQ
24235

Emsisoft Anti-Malware
Trojan.GenericKD.2779864
8.16.03.24.12

ESET NOD32
VBS/TrojanDownloader.Agent.NTW
10.13040

Fortinet FortiGate
VBS/Agent.NSI!tr.dldr
3/24/2016

F-Secure
Trojan.GenericKD.2779864
11.2016-24-03_5

G Data
Trojan.GenericKD.2779864
16.3.25

IKARUS anti.virus
Trojan-Downloader.VBS.Agent
t3scan.2.0.6.0

K7 AntiVirus
Trojan-Downloader
13.213.18762

Kaspersky
Trojan-Downloader.Win32.Agent
14.0.0.467

Malwarebytes
Trojan.Downloader
v2016.03.24.12

McAfee
RDN/Generic Downloader.x
5600.6450

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!bit
1.1.12400.0

MicroWorld eScan
Trojan.GenericKD.2779864
17.0.0.252

NANO AntiVirus
Trojan.Win32.Agent.dxtesu
1.0.14.6204

nProtect
Trojan.GenericKD.2779864
16.02.16.01

Panda Antivirus
Generic Suspicious
16.03.24.12

Qihoo 360 Security
Win32/Trojan.Downloader.10d
1.0.0.1120

Quick Heal
Trojan.Skeeyah.r2
3.16.14.00

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16322

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_BANLOAD.YWNLV
7.2.84

Trend Micro
TROJ_BANLOAD.YWNLV
10.465.24

VIPRE Antivirus
Trojan.Win32.Generic
47264

File size:
507.5 KB (519,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\intimacao-mpf.exe

File PE Metadata
Compilation timestamp:
2/4/2013 9:06:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:twjCkb1QztuSXKVFEaylelZwVjOdqApsn4w4fZJhLR5SCXerYqoIeTHlpNjUOQ9F:YCkbKt3ayl2kCs4NtperN

Entry address:
0x1000

Entry point:
B8, 88, 1A, 51, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 2E, A8, BB, B8, 0E, 99, 84, 0A, 4F, C4, 77, 37, 6E, BC, B8, 92, 1C, 85, F2, BA, 5F, 2B, E7, 71, 23, 30, E1, 2B, CC, 53, 75, B4, 4B, 19, D2, 3C, 4F, 0B, C0, BD, E9, 26, 96, D9, E1, DD, B1, 09, 69, A5, 70, 07, 3E, BB, 25, CA, 19, 2F, C6, C1, 26, AD, F4, FA, AA, DC, 5A, BD, 1B, CD, 6F, 40, 8B, F0, 8F, A1, 41, B4, FF, 6C, 12, 85, 37, 44, 3F, 49, 52, CB, E3, 3B, 79, A1, 83...
 
[+]

Packer / compiler:
PECompact v2

Code size:
154 KB (157,696 bytes)

The file intimacao-mpf.exe has been seen being distributed by the following URL.

Remove intimacao-mpf.exe - Powered by Reason Core Security