cp029738.exe

Online ROM Flash Component for Windows (x64) - Smart Array H240ar, H240nr, H240, H241, H244br, P240nr, P244br, P246br, P440ar, P440, P441, P542D, P741

Hewlett Packard Enterprise Company

This is a setup program which is used to install the application. The file has been seen being downloaded from h20566.www2.hpe.com and multiple other hosts.
Publisher:
Hewlett Packard Enterprise Development LP  (signed by Hewlett Packard Enterprise Company)

Product:
Online ROM Flash Component for Windows (x64) - Smart Array H240ar, H240nr, H240, H241, H244br, P240nr, P244br, P246br, P440ar, P440, P441, P542D, P741

Description:
Online ROM Flash Component for Windows (x64) - Smart Array H240ar, H240nr, H240, H241, H244br, P240nr, P244br, P246br, P440ar, P440, P441, P542D, P741m, P840, P840ar, and P841 Package

Version:
4.02

MD5:
b4d2cb5b19db0cd621b7cf2afd5f1f6c

SHA-1:
b4cee0b5df0096e119095085b1de1ad5f38e4155

SHA-256:
77f9567b15e4d8075d960c540649b597cd7a8d500e12f640a25f8e99a7fab25d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 8:33:23 PM UTC  (today)

File size:
6.4 MB (6,704,936 bytes)

Product version:
4.02

Copyright:
© 1999, 2015 Hewlett Packard Enterprise Development LP

Original file name:
cpqstub.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\cp029738.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/2/2015 1:00:00 AM

Valid to:
12/2/2016 12:59:59 AM

Subject:
CN=Hewlett Packard Enterprise Company, OU=HP Cyber Security, O=Hewlett Packard Enterprise Company, STREET=3000 Hanover Street, L=Palo Alto, S=CA, PostalCode=94304, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3CF170877E235036200BECF49A6312AA

File PE Metadata
Compilation timestamp:
12/1/2015 5:20:20 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
196608:rU/z12tR5h1b4Vwv4N26g4G7KFfXopaMdF1:vtR5vbQwv226k7ugpagF1

Entry address:
0x20960

Entry point:
48, 83, EC, 28, E8, 03, AE, 00, 00, 48, 83, C4, 28, E9, 72, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, 83, 64, 24, 40, 00, 4C, 8D, 44, 24, 40, E8, 63, AF, 00, 00, 48, 8B, D8, 48, 85, C0, 75, 1B, 39, 44, 24, 40, 74, 15, E8, 44, 3E, 00, 00, 48, 85, C0, 74, 0B, E8, 3A, 3E, 00, 00, 8B, 4C, 24, 40, 89, 08, 48, 8B, C3, 48, 83, C4, 20, 5B, C3, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 41, 55, 41, 57, 48, 83, EC, 40, 48, 8B, FA, 4C, 63, E1, 45, 33, FF, 4C, 89, 78, 10, 41, 8B...
 
[+]

Code size:
195.5 KB (200,192 bytes)

The file cp029738.exe has been seen being distributed by the following 3 URLs.

Scan cp029738.exe - Powered by Reason Core Security