mpkview.exe

Mipko OOO

The application mpkview.exe by Mipko OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Mipko OOO  (signed and verified)

Description:
MIPKO Software

Version:
7.4.1.1473

MD5:
e865ce2005f3e923f03b842ff445ddc3

SHA-1:
bceffca81bf6d748fb4d9d5a699ff946843e5819

SHA-256:
2ecadf52956e95778e48e2ccd91bc02baab233fec2398ff771ae5dde6e915c8d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 9:58:46 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Mipko (M)
16.6.27.22

File size:
3.9 MB (4,110,664 bytes)

Product version:
7.4.1.1473

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\mpk\mpkview.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/25/2010 3:00:00 AM

Valid to:
11/25/2012 2:59:59 AM

Subject:
CN=Mipko OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mipko OOO, L=Pskov, S=Pskov, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
744A4A940AA3FE09F15CC2879605C21D

File PE Metadata
Compilation timestamp:
8/22/2012 3:11:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:DSWjc4wwQKdtoETtcV6WR7v07WY4KHTtN51pnohT0q9prC0:Dhjc4jzook6u7sF4KzT51pn24ulX

Entry address:
0x1000

Entry point:
68, 01, 60, C7, 00, E8, 01, 00, 00, 00, C3, C3, D9, BB, C5, 0B, 22, 5E, 78, 6D, 9C, E1, 80, 24, 8E, C3, C3, 6F, 7C, F6, 86, 05, 4E, 38, D3, D6, 23, 4E, 09, 5B, F1, 63, 66, 2C, 3D, E2, 6F, 8E, 0F, AC, 79, B4, 4E, 3E, 61, F9, 87, 76, AF, 3D, 0A, 16, 7D, 92, 48, 17, C1, DC, 24, DF, 61, 5D, 34, 06, 7A, 19, 76, C0, CA, 1B, 61, 90, D8, D1, AD, 3A, E7, 69, 21, 90, ED, DE, BC, 3A, 40, 00, EF, 11, 5D, 3A, 1B, 5D, 1E, 2F, 62, 2F, 9D, A9, 50, 5B, 14, 7D, 00, BC, 44, 50, E5, BD, 4D, 5C, 8F, BB, A6, B5, B5, EA, 6B, AC...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4.9 MB (5,108,736 bytes)

Windows Firewall Allowed Program
Name:
tcp\ip


Remove mpkview.exe - Powered by Reason Core Security