pendencias.exe

LUYARA FELIX DE ARAUJO 05168873359

The executable pendencias.exe has been detected as malware by 27 anti-virus scanners.
Publisher:
LUYARA FELIX DE ARAUJO 05168873359  (signed and verified)

Version:
1.0.0.0

MD5:
ed53a9148461e52a3a648a3b9df7b148

SHA-1:
913aafe125358ba78f003a284d9a3821e0f818c6

SHA-256:
1b7f93476d7caf71b8d9bf3d0effc2c172a6c4cf5ed3423b87972f631cf94c28

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/24/2025 8:41:00 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14901727
238

AegisLab AV Signature
Troj.Banker.MSIL.Banbra.ci!c
2.1.4+

Avira AntiVirus
TR/Spy.Banker.69640.1
8.3.3.4

Arcabit
Trojan.Generic.DE361DF
1.0.0.696

avast!
MSIL:Downloader-MU [Drp]
2014.9-160610

AVG
PSW.Banker6
2017.0.2716

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.16610

Bitdefender
Trojan.Generic.14901727
1.0.20.810

Comodo Security
UnclassifiedMalware
25158

Emsisoft Anti-Malware
Trojan.Generic.14901727
8.16.06.10.07

ESET NOD32
MSIL/Spy.Banker.CC (variant)
10.13591

Fortinet FortiGate
W32/Banbra.CC!tr
6/10/2016

F-Secure
Trojan.Generic.14901727
11.2016-10-06_6

G Data
Trojan.Generic.14901727
16.6.25

Kaspersky
Trojan-Banker.MSIL.Banbra
14.0.0.76

Malwarebytes
Trojan.Agent
v2016.06.10.07

McAfee
Artemis!ED53A9148461
5600.6372

Microsoft Security Essentials
TrojanSpy:MSIL/Banker
1.1.12805.0

MicroWorld eScan
Trojan.Generic.14901727
17.0.0.486

NANO AntiVirus
Trojan.Win32.Banker.dupard
1.0.30.8482

nProtect
Trojan.Generic.14901727
16.06.03.01

Panda Antivirus
Generic Suspicious
16.06.10.07

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1120

Quick Heal
TrojanSpy.Banker.r3
6.16.14.00

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
49852

Zillya! Antivirus
Trojan.Banbra.Win32.24053
2.0.0.2904

File size:
68 KB (69,640 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
LoaderDEL.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pendencias.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/10/2014 1:19:06 PM

Valid to:
11/11/2015 1:19:06 PM

Subject:
CN=LUYARA FELIX DE ARAUJO 05168873359, OU=TI, O=LUYARA FELIX DE ARAUJO 05168873359, L=Imperatriz, S=Maranhao, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D20CD8AF8CA0767E911EE22F03281F76

File PE Metadata
Compilation timestamp:
1/21/2015 4:31:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:hBMvXVoDlqoI19kyfaQnVfkrhJR+iE2HQMC8W:hBMvXVYlq51KcwR+NoQMRW

Entry address:
0x3DFE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8 KB (8,192 bytes)

Remove pendencias.exe - Powered by Reason Core Security