3994cc24-5a9c-4b84-8bde-e17e5a787682.exe

Employee Monitor

Refog Inc.

The application 3994cc24-5a9c-4b84-8bde-e17e5a787682.exe, “Employee Monitor Setup ” by Refog has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from download.refog.com.
Publisher:
Refog   (signed by Refog Inc.)

Product:
Employee Monitor

Description:
Employee Monitor Setup

Version:
7.6.3.1814

MD5:
59676e81dd6ab2883236d7fe4c9e5f40

SHA-1:
febcd9743b5311f3ffe384a4d693b8cad8c31cb0

SHA-256:
37ab8b6ecbb3f34805f83b16ebebed4968c4657df0324315006ec1611a1d7616

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 6:50:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.21.21

File size:
8.1 MB (8,509,392 bytes)

Product version:
7.6.3.1814

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\3994cc24-5a9c-4b84-8bde-e17e5a787682.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/11/2011 7:00:00 PM

Valid to:
2/5/2013 6:59:59 PM

Subject:
CN=Refog Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Refog Inc., L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FC4489003E01028139915C2D888675C

File PE Metadata
Compilation timestamp:
10/9/2012 3:48:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:jzIryfQQx5+5H+Wwc5sR1ShatHIMATzZgv++/3q:nCyf+C2UHLf

Entry address:
0xF3BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 64, ED, 40, 00, E8, E8, 71, FF, FF, 33, C0, 55, 68, 89, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 45, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, BE, F7, FF, FF, E8, 65, F3, FF, FF, 8D, 55, EC, 33, C0, E8, F7, C3, FF, FF, 8B, 55, EC, B8, 4C, 66, 41, 00, E8, 6A, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 4C, 66, 41, 00, B2, 01...
 
[+]

Entropy:
7.9976

Developed / compiled with:
Microsoft Visual C++

Code size:
59 KB (60,416 bytes)

The file 3994cc24-5a9c-4b84-8bde-e17e5a787682.exe has been seen being distributed by the following URL.

http://download.refog.com/refog_setup_em_fd.exe

Remove 3994cc24-5a9c-4b84-8bde-e17e5a787682.exe - Powered by Reason Core Security