1643331_stp.exe

TeamViewer

TeamViewer

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with TeamViewer 9. The file has been seen being downloaded from www.filehippo.com and multiple other hosts.
Publisher:
TeamViewer GmbH  (signed by TeamViewer)

Product:
TeamViewer

Version:
9.0.24951.0

MD5:
1fd9dd2960e01677adc60c84eb0a1550

SHA-1:
aee1775d50abda09db1ef620df3af209ba2c4c7c

SHA-256:
e82a43bc0d0b263b12320392f05e38e6975a8641558c2d7b392b2809554725ef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 10:37:41 AM UTC  (today)

File size:
6.9 MB (7,243,968 bytes)

Product version:
9.0.24951.0

Copyright:
TeamViewer GmbH

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\1643331_stp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/7/2011 9:00:00 PM

Valid to:
8/7/2014 8:59:59 PM

Subject:
CN=TeamViewer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TeamViewer, L=Goeppingen, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D27AFBEA5996F13E5B5624421F16295

File PE Metadata
Compilation timestamp:
2/24/2012 4:19:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:Qh0DpsHrIRu5YOa67EC6yZ/BJjbLoB+IHlwC2v:Qh0dsHERuS7/C6yFB2dHlRm

Entry address:
0x3883

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, 92, 40, 00, FF, 15, 84, 81, 40, 00, 68, 4C, 92, 40, 00, 68, C0, AD, 46, 00, E8, 18, 27, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
27.5 KB (28,160 bytes)

The file 1643331_stp.exe has been discovered within the following programs.

TeamViewer 9  by TeamViewer GmbH
Publisher's description - “Remote control any computer or Mac over the internet within seconds or use TeamViewer for online meetings. Open multiple remote sessions in tabs, just like in your browser.”
www.TeamViewer.com
6% remove it
 
Powered by Should I Remove It?

The file 1643331_stp.exe has been seen being distributed by the following 50 URLs.

http://www.filehippo.com/download/file/.../

http://filehippo.com/es/download/file/.../

http://s.baidu.co.th/cgi/reflex?url=http://dl-vip.appstore.baidu.co.th/.../TeamViewer_9.0.24951.0.exe&appid=19951&sign=E9B3E27920719B9783B6CF0E289CA332

http://download.teamviewer.com/.../TeamViewer_Setup-ckc.exe

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-DNjNpy7vrILW8ZjjolKXrGnnr6Nq0H3ezCyJXTEpwwNouZOr71OS3j4XEdxZe0zY/messages/@.id==AIWti2IABUEsV79fIAjtKNvyKns/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBYeVKCJjsABXpWbdLk5Hr7jUWhjIv2uHVC2R0Wv8Q9VgQ&error=https://mg.mail.yahoo.com/.../iframemsg?id=dfd4008f-5a87-b862-63fc-122e7d647b9c&ymreqid=98842d77-909d-cfb9-01c7-430039010000

http://www.grsuporte.com.br/TeamViewer_Setup-dix_Server2012.exe

http://filehippo.com/download/file/.../

http://downloadeu3.teamviewer.com/877FCF11-7A3D-4769-8E05-925A8C4919A6/FinalDownload/DownloadId-E13E7766E5AD5B38DAEE4CD4B6B25EDD/877FCF11-7A3D-4769-8E05-925A8C4919A6/.../TeamViewer_Setup.exe

http://202.65.242.7/.../TeamViewer_Setup.exe

Latest 30 of 53 download URLs