couponprinter.ocx

Coupons, Inc.

The file couponprinter.ocx by Coupons has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Coupons, Inc.  (signed and verified)

MD5:
f5de1a467999c92487924a903cdfc897

SHA-1:
26b9a5d9e99a4b90edc8d99e782be3356dd01aa3

SHA-256:
fffe5ac11548e83fca9094e7d9c0bf0ae03691e7608c27d33436a257fc1b94d6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/16/2024 10:49:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Coupons (M)
16.11.2.5

File size:
69.4 KB (71,072 bytes)

File type:
OLE control extension (Win32 OCX)

Common path:
C:\windows\couponprinter.ocx

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2009 1:00:00 AM

Valid to:
10/14/2012 12:59:59 AM

Subject:
CN="Coupons, Inc.", OU=Coupons.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Coupons, Inc.", L=Palo Alto, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1EB5F8A924702E69957FE213FE8A3657

Registration
CLSIDs:
{9522B3FB-7A2B-4646-8AF6-36E7F593073C}, {A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}

ProgID:
cpbrkpie.Coupon6Ctrl.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
3/19/2008 6:10:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:+XBCrGz3Dd4vEWnTXX1s02TyMwHwyEKuoTkEye49waoCM:JqDd4nnbRUyzQVUkY4vQ

Entry address:
0x73D7

Entry point:
5B, 16, 53, 02, 00, C4, 08, 02, 00, 61, D6, 37, 5C, 48, 5E, 02, 00, C4, 08, 02, 00, B1, A4, 7D, 5C, 30, 5C, 02, 00, C4, 08, 02, 00, 7B, F4, 7E, 5C, D6, 59, 02, 00, C4, 08, 02, 00, EF, 36, EA, 5C, 5A, 5A, 02, 00, C4, 08, 02, 00, C7, 92, FC, 5C, 64, 5D, 02, 00, C4, 08, 02, 00, EC, 56, 27, 5D, EA, 57, 02, 00, C4, 08, 02, 00, 16, 7B, 2B, 5D, B6, 59, 02, 00, C4, 08, 02, 00, 3E, 24, 3B, 5D, B2, 51, 02, 00, C4, 08, 02, 00, B8, 71, 42, 5E, D4, 53, 02, 00, C4, 08, 02, 00, D1, B5, 8D, 5E, 2A, 5D, 02, 00, C4, 08, 02...
 
[+]

Entropy:
6.1060

Code size:
32 KB (32,768 bytes)

Safe for Initializing Control
CLSID:
{9522B3FB-7A2B-4646-8AF6-36E7F593073C}

CLSID name:
cpbrkpie Control


Remove couponprinter.ocx - Powered by Reason Core Security