setup_ca_hu.exe

Setup TKexe

Torsten Krieg / TKexe, info@tkexe.eu

This is a self-extracting archive and installer. The file has been seen being downloaded from www.iconrepro.hu and multiple other hosts.
Publisher:
Torsten Krieg / TKexe, info@tkexe.eu

Product:
Setup TKexe

Description:
TKexe setup archive

Version:
1.1.0.2

MD5:
331620fc479b51a28cdcd7173a1925e4

SHA-1:
6a13b3902dbb960de23d00d493a4021386e8eb6a

SHA-256:
b5945efe80742f33f8068203eba434807f037493a14582a3eb89cc836ee844b0

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 2:22:59 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6379

File size:
40.5 MB (42,462,472 bytes)

Product version:
1.1.0.2

Copyright:
Copyright by Torsten Krieg, TKexe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup_ca_hu.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:e3/6GZoMAqMLpAYPOboKso0vuIIR2JmywCCpxNlSSjLIJQJV2jyyUhhH5rHYU6DN:K/6GZXAqUpAnboKz0g1ywNpxTIYVKshY

Entry address:
0x30F0

Entry point:
55, 8B, EC, 83, C4, F4, B8, B8, 30, 01, 00, E8, 1C, EB, FF, FF, E8, 43, FF, FF, FF, E8, 7E, FF, FF, FF, E8, 15, FE, FF, FF, E8, 30, E6, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
8.5 KB (8,704 bytes)

The file setup_ca_hu.exe has been seen being distributed by the following 2 URLs.

http://www.iconrepro.hu/.../setup_ca_hu.exe

Scan setup_ca_hu.exe - Powered by Reason Core Security