ipsharkksetup.exe

IpSharkkEvolution

IpSharkk.com

The program is a setup application that uses the Inno Setup installer. This is installed with IpSharkkEvolution. The file has been seen being downloaded from filez.kappa.ro.
Publisher:
IpSharkk.com

Product:
IpSharkkEvolution

Description:
IpSharkkEvolution Setup

Version:
3

MD5:
d19b212d54aefa09b7ac4cb1b80ceba4

SHA-1:
cefcc310fb5aa66dafd460a63eb65cc07370f755

SHA-256:
ec58939240156f7739966e4364cb98a750fe84031f9c7c5beb8097e40b8cc0de

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 3:02:35 PM UTC  (today)

File size:
4.3 MB (4,558,805 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ipsharkksetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:TKtR2yNdXKrfLsQkKLZC0D9KDxDyOQxdoM7c3ou0SjtsLSC4:+XF6rzZCw9KD0Fz9c3wSJsLf4

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9984

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file ipsharkksetup.exe has been discovered within the following program.

IpSharkkEvolution  by IpSharkk.com
Publisher's description - “Ip Sharkk offers you wide choice of IP addresses from all over the world. You can change your IP as often as you want, either manually ot automatically every set period of time (even every 1 minute!).”
ipsharkk.com
3% remove it
 
Powered by Should I Remove It?

The file ipsharkksetup.exe has been seen being distributed by the following URL.

Scan ipsharkksetup.exe - Powered by Reason Core Security