mpkview.exe

Mipko OOO

The application mpkview.exe by Mipko OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Mipko OOO  (signed and verified)

Description:
MIPKO Software

Version:
7.3.2.1461

MD5:
ee92def589cebc00c8972c8026f53606

SHA-1:
4056d4565502bd62979ab4c43a43ebae33b5c40b

SHA-256:
5066db5a6bfd9fc71222d561cf6ef3844c6388e684b36068fc522c1de0029f72

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 10:06:21 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.24.10

File size:
3.8 MB (3,980,616 bytes)

Product version:
7.3.2.1461

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/25/2010 3:00:00 AM

Valid to:
11/25/2012 2:59:59 AM

Subject:
CN=Mipko OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mipko OOO, L=Pskov, S=Pskov, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
744A4A940AA3FE09F15CC2879605C21D

File PE Metadata
Compilation timestamp:
5/29/2012 11:08:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:s/0RsjkF1DObHUpd9Ecv0Bl5SNeKhPtJqCY:s/+xF1SoxEcsvKhPOCY

Entry address:
0x1000

Entry point:
68, 01, F0, C4, 00, E8, 01, 00, 00, 00, C3, C3, D9, BB, C5, 0B, 22, 5E, F9, 6B, E0, 07, 4F, 3D, 09, 15, 93, 5E, F0, 3B, F2, 05, 4E, 38, D3, 63, 8E, 4E, 09, 5B, F1, 63, 66, 64, 3D, E2, 6F, 8E, 0F, AC, 79, B4, 4E, 3E, 61, F8, 6E, 78, B0, 53, E7, EA, A2, 4C, A7, 29, 25, E2, A9, 80, 38, F6, B9, 1A, 7E, 19, 56, B5, 78, 94, 61, 90, D0, D1, AD, 3A, E7, 02, 6B, 90, ED, DE, BC, 3A, 58, B9, 40, 07, 27, 82, 79, 05, D4, 4C, 4B, 3D, 1D, C1, B3, 71, 8D, 1C, 14, 19, 75, F0, 09, DE, 60, DF, 08, D7, 21, C9, 65, 05, BB, 92...
 
[+]

Entropy:
7.8279

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4.9 MB (5,097,984 bytes)

Windows Firewall Allowed Program
Name:
tcp\ip


Remove mpkview.exe - Powered by Reason Core Security