npinstall.exe

Gemius S.A.

The application npinstall.exe by Gemius S.A has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from pl.megapanel.gem.pl.
Publisher:
Gemius S.A.  (signed and verified)

MD5:
ee78b895925c091fe2611aa9d52fb4d9

SHA-1:
9fe394e97c3914f3df0d66e6fd9684b1513d1e2a

SHA-256:
a2348eb99bbc63193f1232349dad91b2ccb3ad2e025dacb5ce58ee1bec3df478

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/16/2024 9:28:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.8.9.12

File size:
2.4 MB (2,512,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\npinstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/3/2014 2:00:00 AM

Valid to:
6/2/2016 1:59:59 AM

Subject:
CN=Gemius S.A., O=Gemius S.A., L=Warszawa, S=mazowieckie, C=PL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
411290C3B6985D1DD4202A51727A340B

File PE Metadata
Compilation timestamp:
1/14/2003 9:27:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:zHOr/qNVaU+lHesRsOR7sX6J2dhUPYWpggQL9houDa7dF:zsqj2desRvJsp0gWpggQL3sX

Entry address:
0x1F150

Entry point:
60, BE, 00, 50, 41, 00, 8D, BE, 00, C0, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
44 KB (45,056 bytes)

The file npinstall.exe has been seen being distributed by the following URL.

Remove npinstall.exe - Powered by Reason Core Security