employee_planner_full.exe

DRPU Employee Planner

DRPU Software Pvt. Ltd.

The application employee_planner_full.exe by DRPU Software Pvt has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from secure.avangate.com.
Publisher:
DRPU Software Pvt. Ltd.   (signed by DRPU Software Pvt. Ltd.)

Product:
DRPU Employee Planner

Version:
5.1.2.3

MD5:
352135cca6aa4f03617b095ceda0a006

SHA-1:
5f3038e269d991289315c95934e03b05029b12c0

SHA-256:
c8573a6042a40040473b65f417d093e518d3d75a2228024f324475606e2d4a60

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/26/2024 6:36:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.3.10.21

File size:
3.2 MB (3,315,240 bytes)

Product version:
5.1.2.3

Copyright:
Copyright © 2007-2016, DRPU Software Pvt. Ltd.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\employee_planner_full.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/24/2015 5:30:00 AM

Valid to:
11/25/2016 5:29:59 AM

Subject:
CN=DRPU Software Pvt. Ltd., O=DRPU Software Pvt. Ltd., STREET=J-80 Patel Nagar - 1, L=Ghaziabad, S=UP, PostalCode=201001, C=IN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F7C2DC208A163E6208855517D0B9B03C

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9975

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file employee_planner_full.exe has been seen being distributed by the following URL.

https://secure.avangate.com/order/servant.php?sid=2Xrl85eqoaKOwnmmft/.../CXbQ==

Remove employee_planner_full.exe - Powered by Reason Core Security