f1ffcd72-8bfe-4049-a38c-142af9756a9f.exe

Simple Driver Updater

Vapc Lux Sarl

The application f1ffcd72-8bfe-4049-a38c-142af9756a9f.exe, “Simple Driver Updater installer” by Vapc Lux Sarl has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Simple Driver Updater by SimpleStar. The file has been seen being downloaded from www.simplestar.com and multiple other hosts.
Publisher:
SimpleStar  (signed by Vapc Lux Sarl)

Product:
Simple Driver Updater

Description:
Simple Driver Updater installer

Version:
5.7.1.10

MD5:
2ff12515b861254294c13515c4c66319

SHA-1:
2ab29ba820605a83b2215f30e8a3217bee871001

SHA-256:
6e66fe821ee0e512f68987e0dd4f5210da0af07d7657c42138d131c5f5e63ea8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:40:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SimpleStar (L)
16.10.17.22

File size:
3.9 MB (4,092,248 bytes)

Product version:
5.7.1.10

Copyright:
Copyright (c) 2016 SimpleStar. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/11/2016 10:11:14 AM

Valid to:
2/10/2017 10:57:32 AM

Subject:
E=Ludovic.trogliero@vapc.lu, CN=Vapc Lux Sarl, O=Vapc Lux Sarl, L=Luxembourg, C=LU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130BA28CC6DC89090DD3923776478D67D

File PE Metadata
Compilation timestamp:
4/10/2010 8:19:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:Vj8lxYdlaGybSgxVuzM/BMZghc7t85yYGG4FFSPMT:Vj8nYdlax/xVaKBM6hh5s/FYPMT

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.8079

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file f1ffcd72-8bfe-4049-a38c-142af9756a9f.exe has been discovered within the following program.

Simple Driver Updater  by SimpleStar
www.simplestar.com/support/simple-driver-updater
About 5% of users remove it
 
Powered by Should I Remove It?

The file f1ffcd72-8bfe-4049-a38c-142af9756a9f.exe has been seen being distributed by the following 4 URLs.

Remove f1ffcd72-8bfe-4049-a38c-142af9756a9f.exe - Powered by Reason Core Security