36bde650_stp.exe

AppWork GmbH

The application 36bde650_stp.exe by AppWork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
AppWork GmbH  (signed and verified)

MD5:
a74d6e45c29b41db07804f39c26e4b90

SHA-1:
cc34fd7c2485df05643d700c12807e012f2768ba

SHA-256:
0ddaa1b5891575f0d9e64b662d10ce9ac3e3ca2cea302f32529669d454a0e999

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:34:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.16.9

File size:
30.8 MB (32,300,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\36bde650_stp.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2014 10:21:29 AM

Valid to:
4/1/2015 9:30:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fuerth, S=Bayern, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218C489DBD3BC8AF35CDB519BA450DC59A

File PE Metadata
Compilation timestamp:
3/19/2014 7:18:28 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:CPUXVzk2OioqacEDYjZbyznv0fFwZCgeooUeW+PN:CPUXVNoq9lynoF8CgxHeWk

Entry address:
0x1B144

Code size:
179.5 KB (183,808 bytes)

Remove 36bde650_stp.exe - Powered by Reason Core Security