polpack2v12.exe

WinACE Self-Extractor

e-merge GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from s6234.chomikuj.pl and multiple other hosts.
Publisher:
e-merge GmbH

Product:
WinACE Self-Extractor

Version:
2.0.0.0

MD5:
16f30d7cbe983cf0d5c98ec73cb2e488

SHA-1:
27ae7bdf6c9e40cf5495ed8833935eccbc6d40c6

SHA-256:
4c1ca7d07bd227a96f36e2a1aa477e28629440e919df035173c9bded9b57dec3

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/27/2024 6:43:38 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.7400

McAfee
Artemis!16F30D7CBE98
5600.6495

Quick Heal
(Suspicious) - DNAScan
2.16.14.00

File size:
237.9 KB (243,592 bytes)

Product version:
2.0.0.0

Copyright:
1997-2001 Marcel Lemke & e-merge GmbH

Trademarks:
1997-2001 Marcel Lemke & e-merge GmbH

Original file name:
win32sfx.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\users\{user}\downloads\polpack2v12.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:s/x/QUH6c0mC+C2CcOwJ2jQB1b+Hc7T7Vt:iTac0ACOOwEQBsHc5t

Entry address:
0x49042

Entry point:
B8, 00, 90, 44, 00, 68, B4, 22, 41, 00, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 66, 9C, 60, 50, 68, 00, 00, 40, 00, 8B, 3C, 24, 8B, 30, 66, 81, C7, 80, 07, 8D, 74, 06, 08, 89, 38, 8B, 5E, 10, 50, 56, 6A, 02, 68, 80, 08, 00, 00, 57, 6A, 19, 6A, 06, 56, 6A, 04, 68, 80, 08, 00, 00, 57, FF, D3, 83, EE, 08, 59, F3, A5, 59, 66, 83, C7, 68, 81, C6, E6, 00, 00, 00, F3, A5, FF, D3, 58, 8D, 90, B8, 01, 00, 00, 8B, 0A, 0F, BA, F1, 1F, 73, 16, 8B, 04, 24, FD, 8B, F0, 8B, F8, 03, 72, 04, 03, 7A, 08, F3...
 
[+]

Packer / compiler:
Petite 2.2

Code size:
63.5 KB (65,024 bytes)

The file polpack2v12.exe has been seen being distributed by the following 2 URLs.

Scan polpack2v12.exe - Powered by Reason Core Security