mp68-win-mp250-1_05-ea24.exe

Canon Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from d2.driverscollection.com and multiple other hosts.
Publisher:
Canon Inc.  (signed and verified)

MD5:
3950a91f62a174c33addf646a20f341e

SHA-1:
cd3bd87d151ca98141e594b2def7b33bb2dbfd84

SHA-256:
26df363d922f43055fb287cb7c9a12bcddf8177fbaa0cb368b417c67a216896a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 11:58:06 PM UTC  (a few moments ago)

File size:
20.1 MB (21,060,752 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mp68-win-mp250-1_05-ea24.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/15/2012 7:00:00 PM

Valid to:
4/16/2013 6:59:59 PM

Subject:
CN=Canon Inc., OU=Inkjet System Development Center, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Canon Inc., L=Kawasaki-shi, S=Kanagawa, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
72ACD79546C6E0B523B123D763EFE617

File PE Metadata
Compilation timestamp:
11/2/2009 2:24:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:D6NpJxUC1VZkDDlidur9m2ck6ze3WaOFbFtZJRSIC/1T5p/SCzLG89Z:D6LZkdismE6CaJX/vChzKCznb

Entry address:
0x1479F

Entry point:
E8, 02, 67, 00, 00, E9, 17, FE, FF, FF, 3B, 0D, D8, C9, 42, 00, 75, 02, F3, C3, E9, 82, 67, 00, 00, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 18, 48, 41, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, 54, E6, 00, 00, 8B, 45, 0C, 8B, 40, 04, 83...
 
[+]

Entropy:
7.9984  (probably packed)

Code size:
144 KB (147,456 bytes)

The file mp68-win-mp250-1_05-ea24.exe has been discovered within the following program.

SnapPea  by Wandou Labs
The software currently distributes the app through the OpenCandy monetization platform which is known to distribute adware.
snappea.com
25% remove it
 
Powered by Should I Remove It?

The file mp68-win-mp250-1_05-ea24.exe has been seen being distributed by the following 42 URLs.

https://d2.driverscollection.com/1b015bb5439dcba/792103b5fff4de62d760ac50d601cf4551dfe1bf2264b186be4ce0f15ae8a67d47b30efb95e2fc9ee894934b8156f654574dc9de/3/32/10/.../mp68-win-mp250-1_05-ea24.exe

http://pdisp01.c-wss.com/.../WWUFORedirectTarget.do?id=MDEwMDAwNDYyODAx&cmp=ABX&lang=SE

http://pdisp01.c-wss.com/.../WWUFORedirectTarget.do?id=MDEwMDAwNDYyODAx&cmp=ABX&lang=FI

http://s02.mydiv-downloads.net/download/aHR0cDovL2RyaXZlcnMubXlkaXYubmV0L2Rvd25sb2FkLUNhbm9uLVBJWE1BLU1QMjUwLVByaW50ZXItRHJpdmVyLmh0bWw=/5f846/5888b22b69713/drivers/dfiles/ru/Canon-PIXMA-MP250-Printer-Driver/.../mp68-win-mp250-1_05-ea24.exe

http://www.pikuru.com/?miror=MTQ4MDk1MjY3MTsxOzY4NA==

http://pdisp01.c-wss.com/.../WWUFORedirectTarget.do?id=MDEwMDAwNDYyODAx&cmp=ABX&lang=DK

http://pdisp01.c-wss.com/.../WWUFORedirectTarget.do?id=MDEwMDAwNDYyODAx&cmp=ABS&lang=EN

http://mcdrivers.driverscloud.com/drivers/395/.../mp68-win-mp250-1_05-ea24.exe

http://www.siliconguide.com/drivers/download/.../

http://www.pikuru.com/?miror=MTQ2OTE0MDM4NDsyOzY4NA==

https://d2.driverscollection.com/1d3f7916e59f4f4/1f768f5141fd4d07f776f93b80b45db2522d1b751533bf9af1871bdef6cc3841eed6e9bedeec22855dfb0ad322d75aa85729f23a/3/32/10/.../mp68-win-mp250-1_05-ea24.exe

http://d2.driverscollection.com/77b4f69544c6/2eedbf7a0449d5a611dacd9c1fc067a0a52779e8c1e61778646c5e885f74992c27c3a504ea33b9e917b0506cf55839bf52aba2a0/3/32/10/.../mp68-win-mp250-1_05-ea24.exe

http://d2.driverscollection.com/1b015ba9e407cd8/267588eb7d448e4822bc74e34b095517677a69b2246570f7bc1c40a3fb70f88fe5e372d5fe6e2508d230e46ce95bd4c152e2b701/3/32/10/.../mp68-win-mp250-1_05-ea24.exe

https://filedir.com/.../516951

temp:mp68-win-mp250-1_05-ea24.exe

Latest 30 of 42 download URLs