cpp-passwordrevealer.exe

Dave Hope

Publisher:
Dave Hope  (signed and verified)

MD5:
5d8b3e02c696c3a23abbb206418d09a2

SHA-1:
1af69782eb06085a699e14de14189efee8ad979d

SHA-256:
2b2641a377fdb3ba2fe617c573e4e6b9749192ae7c1059e868d1067eb9524085

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 2:08:03 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14319

File size:
31.8 KB (32,528 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\cpp-passwordrevealer.exe

Digital Signature
Signed by:

Authority:
Dave Hope

Valid from:
12/24/2006 12:36:01 PM

Valid to:
12/31/2039 6:59:59 PM

Subject:
CN=Dave Hope

Issuer:
CN=Dave Hope

Serial number:
DB26464BB2587EA34BFCA010A106F5F6

File PE Metadata
Compilation timestamp:
5/27/2007 6:20:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
384:lFFArygcaqvwGPSK9dct8K3MXUJaLCcsoZ:TFNgFGPSOdctpIL3RZ

Entry address:
0x1240

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 60, 51, 40, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, 78, 51, 40, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 6C, 51, 40, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 5D, E9, 97, 06, 00, 00, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 81, EC, A8, 00, 00, 00, E8, 52, 03, 00, 00, 8B, 45, 08, 89, 45, AC, C7, 45, C0, 00, 20, 40, 00, C7, 45, A0, E8, 14, 40, 00, C7, 45, 9C, 08, 00, 00, 00, C7, 45, 98, 30, 00, 00, 00...
 
[+]

Entropy:
5.2615

Packer / compiler:
MingWin32 GCC, 0x3.x

Code size:
4 KB (4,096 bytes)

The file cpp-passwordrevealer.exe has been seen being distributed by the following 3 URLs.

&onid=2094&oid=3001-2094_4-10694019&rsid=cbsidownloadcomsite&sl=fr&sc=us&topicguid=utilities/sys&topicbrcrm=&pid=10694020&mfgid=6285359&merid=6285359&ctype=dm&cval=NONE&devicetype=desktop&pguid=a7849fd4909802916be62db9&viewguid=bhqhqv@rnTkBYbS2kQX3JrSSj1ntUxF@A@lz&destUrl=http://files.downloadnow.com/s/software/10/69/40/.../CPP-PasswordRevealer.exe

Scan cpp-passwordrevealer.exe - Powered by Reason Core Security