mu1cadativtur.exe

Área de Negócios - Atividades

www.microuniversity.com.br

This is a setup program which is used to install the application. The file has been seen being downloaded from dc122.4shared.com.
Publisher:
www.microuniversity.com.br

Product:
Área de Negócios - Atividades

Description:
Área de Negócios - Atividades (Módulo Turma)

Version:
1.00.0002

MD5:
5f82133a29d503020208b0aa050e3ccd

SHA-1:
90c8828a19c8a14cbc9b36deca80234e7a80fcad

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 3:43:20 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Trojan.VBInject!1.64FA
23.00.65.16517

File size:
396 KB (405,504 bytes)

Product version:
1.00.0002

Original file name:
mu1cadativtur.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\mu1cadativtur.exe

File PE Metadata
Compilation timestamp:
11/8/2014 12:19:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:NTOyjiKDrjiK/2T42Q6O9eXdK1pun8EA5oPz0VdyO9wd5Iwd5uwgtfkzN/tXNDjq:Ny9KDKK/wbXdMuSoPz0aOYNDjZJ

Entry address:
0x25C0

Entry point:
68, 24, E7, 42, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 52, 55, 71, 3C, D4, 5C, CE, 48, A8, EA, 55, AC, 5E, 28, E5, D2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 63, 6F, 6D, 20, 65, 73, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 61, 64, 65, 20, 22, 0D, 0A, 00, 00, 00, 00, FF, CC, 31, 00, 20, 79, B7, 46, 41, 64, 27, 0A, 48, AC, 73, 4B, 21, 69, E6, F6, 02, E4, 84, 9D, 3C, DD, 71, 84, 47, A1, 41, 8C, BB, 6B, 1F, 5A, 18, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
380 KB (389,120 bytes)

The file mu1cadativtur.exe has been seen being distributed by the following URL.

Scan mu1cadativtur.exe - Powered by Reason Core Security