tagplus_pdv_4.0__kgh0dha6ly9hchaudgfncgx1cy5jb20uynivznjhbm1izxzhlykod3nlcnzpy2upkg1tcm1temf6enqpkde

Tag Software Desenvolvimento e Comercio de Sistemas LTDA

The file tagplus_pdv_4.0__kgh0dha6ly9hchaudgfncgx1cy5jb20uynivznjhbm1izxzhlykod3nlcnzpy2upkg1tcm1temf6enqpkde by Tag Software Desenvolvimento e Comercio de SistemasA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from app.tagplus.com.br.
Publisher:
TagPlus PDV   (signed by Tag Software Desenvolvimento e Comercio de Sistemas LTDA)

Product:
TagPlus PDV

Version:
TagPlus PDV 4.0

MD5:
96f6a8b4eb0a1869b3479ee53db896e9

SHA-1:
67fd4700a0542444f5bd0d9a6ee0fbe1753598c9

SHA-256:
6ba6cc5af3252a4b81e5bb0ab527839070af85608fae1f9c3bd060b69dfeaa84

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/17/2024 9:33:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.1.23.12

File size:
36.6 MB (38,416,992 bytes)

Product version:
4.0

Copyright:
Gat Tecnologia e Desenvolvimento de Sistema LTDA

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\tagplus_pdv_4.0__kgh0dha6ly9hchaudgfncgx1cy5jb20uynivznjhbm1izxzhlykod3nlcnzpy2upkg1tcm1temf6enqpkdep.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/18/2013 11:06:02 PM

Valid to:
7/2/2016 6:30:02 PM

Subject:
CN=Tag Software Desenvolvimento e Comercio de Sistemas LTDA, O=Tag Software Desenvolvimento e Comercio de Sistemas LTDA, L=Belo Horizonte, S=Minas Gerais, C=BR

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
07E137D21F92C5

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file tagplus_pdv_4.0__kgh0dha6ly9hchaudgfncgx1cy5jb20uynivznjhbm1izxzhlykod3nlcnzpy2upkg1tcm1temf6enqpkde has been seen being distributed by the following URL.

http://app.tagplus.com.br/franmbeva/suporte/download_arquivos/realiza_download/.../