paula fernandes part anjos do resgate oracao pela familia.exe

BR SOFTWARE LLC

The application paula fernandes part anjos do resgate oracao pela familia.exe by BR SOFTWARE has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.klumag.net.
Publisher:
BR SOFTWARE LLC  (signed and verified)

MD5:
8419f49693dbac32fdb130a4af4bf363

SHA-1:
502274c3fc9ac054cd6c1b0e961292145f7cf8cf

SHA-256:
1a36fafe1f70e711f14dcaf670a5b943a341dd68155d934f8aa3d7f300096335

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 11:20:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BR Software (M)
16.9.15.23

File size:
674 KB (690,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\paula fernandes part anjos do resgate oracao pela familia.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
7/30/2014 2:33:38 AM

Valid to:
7/30/2015 2:33:38 AM

Subject:
E=brsoftwarellc@gmail.com, CN="Open Source Developer, BR SOFTWARE", O=BR SOFTWARE LLC, C=US

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
1794379E94C170D3D7163C1D5D2C35CD

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:a+GBE6yIsECRpg2lS1dYk2yGOObrXHQkcYGxF:J02IIQDExNTQGGxF

Entry address:
0x7AA24

Entry point:
55, 8B, EC, 83, C4, F0, B8, 84, A7, 47, 00, E8, D0, B5, F8, FF, A1, 40, D1, 47, 00, 8B, 00, E8, E4, DC, FD, FF, A1, 40, D1, 47, 00, 8B, 00, BA, 9C, AA, 47, 00, E8, CB, D8, FD, FF, 8B, 0D, 28, CE, 47, 00, A1, 40, D1, 47, 00, 8B, 00, 8B, 15, E4, 96, 47, 00, E8, D3, DC, FD, FF, 8B, 0D, F0, CF, 47, 00, A1, 40, D1, 47, 00, 8B, 00, 8B, 15, 08, 8E, 47, 00, E8, BB, DC, FD, FF, A1, 40, D1, 47, 00, 8B, 00, E8, 2F, DD, FD, FF, E8, 76, 93, F8, FF, 00, 00, FF, FF, FF, FF, 11, 00, 00, 00, 50, 72, 6F, 74, 65, 74, 6F, 72...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
487 KB (498,688 bytes)

The file paula fernandes part anjos do resgate oracao pela familia.exe has been seen being distributed by the following URL.

http://www.klumag.net/ids/.../Paula Fernandes Part Anjos Do Resgate Oracao Pela Familia.exe