ppckeywordwrapper.exe

MD5:
912e51a566b581cacf64bb07187b9911

SHA-1:
78ab3a2160b19978af9cfd28bad75074e4e432ef

SHA-256:
ef04cf766ec3a7efd1d95ea58a98720d2f5a2d2f27c036df857ccc2eaa8ff4b8

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/30/2024 7:07:01 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
629 KB (644,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ppckeywordwrapper.exe

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:8nA5i6TmaCf9mAEOG6KrHyVOM4rkv4Tv/qUz+NPRyK3mN4a:8YLJA9NEEKrHnR7nwNPgK3mN

Entry address:
0x869EC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 94, 66, 48, 00, E8, 34, F4, F7, FF, A1, 34, 94, 48, 00, 8B, 00, E8, 3C, 23, FD, FF, 8B, 0D, 7C, 90, 48, 00, A1, 34, 94, 48, 00, 8B, 00, 8B, 15, B4, 58, 48, 00, E8, 3C, 23, FD, FF, A1, 34, 94, 48, 00, 8B, 00, E8, B0, 23, FD, FF, E8, 6F, D3, F7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6032

Developed / compiled with:
Microsoft Visual C++

Code size:
535 KB (547,840 bytes)

The file ppckeywordwrapper.exe has been seen being distributed by the following URL.

Scan ppckeywordwrapper.exe - Powered by Reason Core Security