monpwr11.exe

MonPwr

Caffinc

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MonPwr’. The file has been seen being downloaded from www.caffinc.com.
Publisher:
Caffinc

Product:
MonPwr

Version:
1.01.0005

MD5:
71bfd13fcf5deba6c4697e3090910893

SHA-1:
1ccd0ff21abd5efe2caa09e8e1f7c48c220c5a80

SHA-256:
9b70083b11ec2e434ea1c5d81b7154d54a2e37ab85b71655163a8c0c5ec44814

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/29/2024 3:40:34 AM UTC  (today)

File size:
176 KB (180,224 bytes)

Product version:
1.01.0005

Original file name:
monpwr11.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\monpwr11.exe

File PE Metadata
Compilation timestamp:
2/22/2011 2:19:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:oKl8NKKRzkZHibYotpKMKwnGJQkpPY2gg4wW7nN1INbGHP3VyExVBSlhlpKFAcAa:7l4RzDlPwv87PINb2BE9

Entry address:
0x19F4

Entry point:
68, 44, 67, 40, 00, E8, F0, FF, FF, FF, 00, 00, 40, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 97, 4C, 0E, DD, 6C, 41, 5E, 41, 9F, F9, F1, 04, 92, 6A, E9, 58, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4D, 6F, 6E, 50, 77, 72, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 88, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 06, 00, 00, 00, 55, 46, E8, 33, E9, 38, DF, 43, B6, 19, 9C, B9, 6D, 6B, DE, E6, 01, 00, 00, 00, A0, 00, 00, 00, B0, 00, 00, 00, 01, 00, 00, 00...
 
[+]

Entropy:
6.0978

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
152 KB (155,648 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MonPwr

Command:
C:\users\{user}\downloads\monpwr11.exe


The file monpwr11.exe has been seen being distributed by the following URL.

Scan monpwr11.exe - Powered by Reason Core Security