pb1.exe

Loader CA

Dias

The executable pb1.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from engenhariatm.com.
Publisher:
Dias

Product:
Loader CA

Version:
2.0.0.0

MD5:
df128faafdca899f77701c92905a895c

SHA-1:
2dc1e59831eb9c9e5c5213fd17aeba07f96e47be

SHA-256:
f825e317b0570db0051f0b32c21bd1b5977d4a53a2ba4bf59804225a0112a76f

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
12/26/2024 5:30:37 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.MSILPerseus.6528
359

Arcabit
Trojan.MSILPerseus.D1980
1.0.0.646

Baidu Antivirus
Hacktool.MSIL.DllInject
4.0.3.16211

Bitdefender
Gen:Variant.MSILPerseus.6528
1.0.20.210

Emsisoft Anti-Malware
Gen:Variant.MSILPerseus.6528
8.16.02.11.06

ESET NOD32
MSIL/DllInject.LN potentially unsafe (variant)
10.12946

F-Secure
Gen:Variant.MSILPerseus.6528
11.2016-11-02_5

G Data
Gen:Variant.MSILPerseus.6528
16.2.25

MicroWorld eScan
Gen:Variant.MSILPerseus.6528
17.0.0.126

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Rising Antivirus
PE:Trojan.Confuser!1.A352 [F]
23.00.65.16209

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
46830

File size:
127.5 KB (130,560 bytes)

Product version:
2.0.0.0

Copyright:
Copyright © 2015

Original file name:
Loader.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pb1.exe

File PE Metadata
Compilation timestamp:
1/28/2016 2:54:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:DnAtpoamkSAipVJ1Jowz4I746OKmDqQok/J:Dudmk9i11SwkI746O/qzk/J

Entry address:
0x1F80E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
118.5 KB (121,344 bytes)

The file pb1.exe has been seen being distributed by the following URL.

Remove pb1.exe - Powered by Reason Core Security