qubnfe.exe

qubnfe

Quartzo Desenvolvimento de Software Ltda.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘qubnfe’.
Publisher:
Quartzo Desenvolvimento de Software Ltda.  (signed by Quartzo Desenvolvimento de Software Ltda.)

Product:
qubnfe

Version:
4.00.0008

MD5:
b60bbe7f3f320f680909f8cbd269c78d

SHA-1:
f4311427f5d845f840f13f2c8bcdcc6a8053afc3

SHA-256:
897f2c1f55fdcba715cc724e323a5a606aa5d4a6a51c1feac54e7245dc6d05ae

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/5/2024 6:32:31 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/VBTrojan.17D1
v6.4.7.1.166

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0302
7.2.14

File size:
1.1 MB (1,175,352 bytes)

Product version:
4.00.0008

Original file name:
qubnfe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\qubnfe\qubnfe.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/5/2013 9:15:02 AM

Valid to:
12/19/2014 4:51:54 PM

Subject:
CN=Quartzo Desenvolvimento de Software Ltda., O=Quartzo Desenvolvimento de Software Ltda., L=Itatiba, S=São Paulo, C=BR

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B298821C190FF

File PE Metadata
Compilation timestamp:
5/13/2014 4:35:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:SowfkokB0M36loxoMyIdvXF/3Sdv4PI7Cr4fxfNBbv/qRpvUe25:4fkvB0MKloxoO1J3PI+0vpnKpMe25

Entry address:
0x4F0A30

Entry point:
60, BE, 00, B0, 7D, 00, 8D, BE, 00, 60, C2, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
1.1 MB (1,138,688 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
qubnfe

Command:
C:\Program Files\qubnfe\qubnfe.exe \auto


Scan qubnfe.exe - Powered by Reason Core Security