8443181.exe

Caps product

Dominik Reichl

The executable 8443181.exe has been detected as malware by 5 anti-virus scanners.
Publisher:
Caps product Technologies Inc.  (signed by Dominik Reichl)

Product:
Caps product

Version:
1.03.0002

MD5:
6f3f8b9de60a2bf24efe0a6c8ab9c534

SHA-1:
3a8c608340a7c10d094822ae6a73254ff25d5c90

SHA-256:
de81159e98dc6c684252420a8b6af81fbbd441f8daa2a3bbf5051ef9ee6add5a

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/25/2024 5:17:37 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160708-3

Dr.Web
Trojan.Kovter.197
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Symmi.60452
11.5.0.6191

ESET NOD32
Win32/Injector.CRBQ trojan
8.0.319.0

Norman
Gen:Variant.Symmi.60719
22.05.2016 07:18:28

File size:
332.3 KB (340,256 bytes)

Product version:
1.03.0002

Original file name:
Caps product.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\8443181.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
3/17/2015 9:54:09 AM

Valid to:
3/16/2016 9:54:09 AM

Subject:
E=cert@dominik-reichl.de, CN="Open Source Developer, Dominik Reichl", O=Dominik Reichl, C=DE

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
641E4CE9B57552F56C2644B2088CD6

File PE Metadata
Compilation timestamp:
1/27/2016 1:50:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:P/////WNsI/igkZIPWQ1A3/RsUVQU7IYYXbh0sljcSeq3X:ekKw35sUVhjYXFbPeq3X

Entry address:
0x125C

Entry point:
68, 88, 0E, 44, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 23, F4, A0, 27, F4, BA, A4, 4F, BE, BB, 36, DB, 32, E7, 6A, D8, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 69, 6F, 6E, 20, 20, 20, 4C, 65, 65, 72, 74, 61, 6B, 74, 65, 00, 3D, 20, 20, 20, 20, 22, 00, 00, 00, 00, FF, CC, 31, 00, 03, 5C, 18, 88, 27, 67, 25, 83, 4E, 83, 2B, A3, 0A, CB, 0E, 24, E3, CF, 84, FE, 48, 41, 8B, 73, 43, A7, BE, 45, BE, 82, FF, 2D, CB, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.2688

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
308 KB (315,392 bytes)

Remove 8443181.exe - Powered by Reason Core Security