play back cancao do ceu anderson freire conexao mp3.exe

g3CvT78vSMa0N0LPai7QvtmUw

GENCO LABS LLC

The application play back cancao do ceu anderson freire conexao mp3.exe by GENCO LABS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.wikizu.net.
Publisher:
g3CvT78vSMa0N0LPai7QvtmUwmghB  (signed by GENCO LABS LLC)

Product:
g3CvT78vSMa0N0LPai7QvtmUw

Version:
5.9.1.7

MD5:
e562398ce6fd6c811662f200dcd2d0d8

SHA-1:
ccd28991b0d97a39aba569f9b31e53900dd64cd0

SHA-256:
d90dc025886d16b97442ddbf73088d1357bd97cfcbd1378c4459c8597e6daf81

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 6:54:04 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BR Software (M)
17.3.3.11

File size:
69.4 KB (71,112 bytes)

Trademarks:
g3CvT78vSMa0N0LP

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\play back cancao do ceu anderson freire conexao mp3.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
4/2/2015 10:13:39 AM

Valid to:
10/20/2015 7:14:36 PM

Subject:
CN=GENCO LABS LLC, O=GENCO LABS LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00DCC6832CB96E85F8

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file play back cancao do ceu anderson freire conexao mp3.exe has been seen being distributed by the following URL.

http://www.wikizu.net/ids/id50/.../ Play Back Cancao Do Ceu Anderson Freire Conexao Mp3.exe