prosuite_demo.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.logomanager.co.uk and multiple other hosts.
MD5:
e755f0bac8e6d9e5643ac90a810a695e

SHA-1:
0e32e71d5629ccf75aeea065df773d03c25f2616

SHA-256:
a5930ab9e6016efb85276d0d1f135f40a7ffb249feef5605f6cd7a16147d172b

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 3:30:17 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan-PWS.Win32.Agent
t3scan.1.9.5.0

File size:
2.7 MB (2,877,274 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\prosuite_demo.exe

File PE Metadata
Compilation timestamp:
8/8/2007 9:46:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:DM5vg0s4M/y7syirhHhMTvd9Dukk3Cftir5+yz0CTXBDV/o6mmzslafp:IZx+XyitBUPDfRsrYy7XdMCx

Entry address:
0x1797

Entry point:
6A, 00, FF, 15, 3C, 10, 40, 00, 50, E8, 43, FE, FF, FF, 50, FF, 15, 34, 10, 40, 00, CC, CC, CC, CC, 8D, 42, FF, 5B, C3, 8D, A4, 24, 00, 00, 00, 00, 8D, 64, 24, 00, 33, C0, 8A, 44, 24, 08, 53, 8B, D8, C1, E0, 08, 8B, 54, 24, 08, F7, C2, 03, 00, 00, 00, 74, 15, 8A, 0A, 83, C2, 01, 3A, CB, 74, CF, 84, C9, 74, 51, F7, C2, 03, 00, 00, 00, 75, EB, 0B, D8, 57, 8B, C3, C1, E3, 10, 56, 0B, D8, 8B, 0A, BF, FF, FE, FE, 7E, 8B, C1, 8B, F7, 33, CB, 03, F0, 03, F9, 83, F1, FF, 83, F0, FF, 33, CF, 33, C6, 83, C2, 04, 81...
 
[+]

Entropy:
7.9983

Packer / compiler:
FASM v1.3x

Code size:
5.5 KB (5,632 bytes)

The file prosuite_demo.exe has been seen being distributed by the following 3 URLs.

http://www.logomanager.co.uk/.../download.php?action=getdemo&product=54

Scan prosuite_demo.exe - Powered by Reason Core Security