pendências.exe

LUYARA FELIX DE ARAUJO 05168873359

The executable pendĂȘncias.exe has been detected as malware by 10 anti-virus scanners.
Publisher:
LUYARA FELIX DE ARAUJO 05168873359  (signed and verified)

Version:
1.0.0.0

MD5:
3c487c30220d2d359bdd244f7244cfa1

SHA-1:
faec8176cd0b3d1172d7d24e4c5367e58be1ad8d

SHA-256:
85024a1771b00b0adfc736e1f442e94e878de341fa2af5ca0779e44e07461e96

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/24/2025 8:41:01 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Banker
2015.02.14

AVG
PSW.Banker6
2017.0.2832

Baidu Antivirus
Trojan.MSIL.Banker
4.0.3.16216

ESET NOD32
MSIL/Spy.Banker.CC (variant)
10.11173

Fortinet FortiGate
MSIL/Banker.CC!tr.spy
2/16/2016

IKARUS anti.virus
Trojan.MSIL.Spy
t3scan.1.8.6.0

Malwarebytes
Trojan.Agent
v2016.02.16.10

McAfee
RDN/PWS-Banker!ds
5600.6488

Trend Micro House Call
Suspicious_GEN.F47V0204
7.2.47

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
37530

File size:
68 KB (69,640 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Carregando.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\tudo\pendências.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/10/2014 1:19:06 PM

Valid to:
11/11/2015 1:19:06 PM

Subject:
CN=LUYARA FELIX DE ARAUJO 05168873359, OU=TI, O=LUYARA FELIX DE ARAUJO 05168873359, L=Imperatriz, S=Maranhao, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D20CD8AF8CA0767E911EE22F03281F76

File PE Metadata
Compilation timestamp:
2/4/2015 12:58:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:x0UvnVoDlqoI19kyfaQnVfkrhJR+iE2HQMC8Wg:x0UvnVYlq51KcwR+NoQMRWg

Entry address:
0x3F7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8 KB (8,192 bytes)

Remove pendências.exe - Powered by Reason Core Security