hpinstaller.exe

HP Webpack

Hewlett-Packard

This is a self-extracting archive and installer. The file has been seen being downloaded from doc-0s-4k-docs.googleusercontent.com and multiple other hosts.
Publisher:
Hewlett-Packard Company  (signed by Hewlett-Packard)

Product:
HP Webpack

Version:
1.4.1926.0

MD5:
da1579c6b3b2378f6df09bb184f6e315

SHA-1:
f944f211c2a2f4c846bfe4ab8707acb1fd97c52d

SHA-256:
f9fe6c45a02f002fcdb16fcdf7462059761a4813d3ce3b5e40e8114eb24022e1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:43:30 AM UTC  (today)

File size:
168.8 MB (177,004,144 bytes)

Product version:
1.4.1926.0

Copyright:
Hewlett-Packard Company

Original file name:
7zS.sfx

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\hpinstaller.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/3/2015 7:00:00 PM

Valid to:
3/3/2016 6:59:59 PM

Subject:
CN=Hewlett-Packard, OU=Global Cyber Security, O=Hewlett-Packard, POBox=Mailstop PAL20-A7K, STREET=3000 Hanover St., L=Palo Alto, S=California, PostalCode=94304-1112, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00871FF341E259949C6F9897442ACE2AEB

File PE Metadata
Compilation timestamp:
10/20/2011 3:48:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3145728:rCr9ETxyIHu7Xft8F3E3LwePw58u9WmnK4SY9iLvgRtBLAfeWLHrT/:rCrWXHujc4lcX5S2iLvcnyLLz

Entry address:
0x1CCBD

Entry point:
E8, CE, 56, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, C8, EF, 42, 00, E8, ED, 27, 00, 00, 6A, 0E, E8, ED, 1C, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, F0, 36, 43, 00, BA, EC, 36, 43, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 89, EB, FF, FF, 59, FF, 76, 04, E8, 80, EB, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, DC, 27, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, B8, 1B, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
8.0000  (probably packed)

Code size:
153 KB (156,672 bytes)

The file hpinstaller.exe has been seen being distributed by the following 10 URLs.

https://doc-0s-4k-docs.googleusercontent.com/docs/securesc/1kdjcdts4cli2i4j15asike633m2pu8u/9p866fa7ik4blrk5rrdmil5u03r8p2p3/1480269600000/.../13655173142878922547/0B0Ts1c9-tOBlamxKWkhlU1RKb1U?e=download

https://www.printerdriverforwindows.com/download/.../

http://h30439.www3.hp.com/pub/softlib/software13/COL56267/.../HP_Color_LJ_Pro_MFP_M277-full-solution-15245.exe

http://whp-aus1.cold.extweb.hp.com/pub/softlib/software13/COL56267/.../HP_Color_LJ_Pro_MFP_M277-full-solution-15245.exe