npinstall.exe

Gemius S.A.

The application npinstall.exe by Gemius S.A has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from pl.panelmena.gemius.com.
Publisher:
Gemius S.A.  (signed and verified)

MD5:
c561e99b9a53a94e0167f22f05e0d193

SHA-1:
293da81009ac937ab5aec77f3eb9f025d3d05a90

SHA-256:
229f2536ac636f2c8e96ea832b2ee9faf68f170c4e501fd15450479e9d3882ec

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/27/2024 5:01:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.8.1.7

File size:
2.3 MB (2,399,840 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\npinstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/3/2014 3:00:00 AM

Valid to:
6/2/2016 2:59:59 AM

Subject:
CN=Gemius S.A., O=Gemius S.A., L=Warszawa, S=mazowieckie, C=PL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
411290C3B6985D1DD4202A51727A340B

File PE Metadata
Compilation timestamp:
1/14/2003 11:27:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:Fnoe1EW0tBEdJmnOJxeTq3V/RabdJopwFX+xfqMo96R+6x:FnoecBO/HWq3VAbboQXPMpR+o

Entry address:
0x1F150

Entry point:
60, BE, 00, 50, 41, 00, 8D, BE, 00, C0, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.9992

Packer / compiler:
UPX 2.90LZMA

Code size:
44 KB (45,056 bytes)

The file npinstall.exe has been seen being distributed by the following URL.

Remove npinstall.exe - Powered by Reason Core Security