setupv0.exe

Diskovery

Pipemetrics SA

Publisher:
Pipemetrics SA  (signed and verified)

Product:
Diskovery

Version:
0.09.0004

MD5:
326ca5941ea49cf15a9db6091f25d3ec

SHA-1:
6ef7ba084292512049cb67d6cc8c991c465906be

SHA-256:
93ae81e5449b318e23deeeb2dd6a7cbeaadf2e0aa9c86a02d53ac077969ece86

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 2:32:25 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Injector.CZRJ trojan
8.0.319.0

File size:
1.6 MB (1,724,088 bytes)

Product version:
0.09.0004

Original file name:
diskovery-0.9.4.0.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Taiwanese)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setupv0.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/11/2015 1:00:00 AM

Valid to:
8/16/2016 2:00:00 PM

Subject:
CN=Pipemetrics SA, O=Pipemetrics SA, L=Lausanne, S=Vaud, C=CH, PostalCode=1003, STREET="38, rue de Petite Chene", SERIALNUMBER=CH-550.1.115.467-4, OID.1.3.6.1.4.1.311.60.2.1.2=Vaud, OID.1.3.6.1.4.1.311.60.2.1.3=CH, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08259A443AC2D7800E7E52F491D88F94

File PE Metadata
Compilation timestamp:
6/4/2016 7:41:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:Ci5/P3zFTmxOJypfj5N406DIi+22UKsnFE2:f/PFnQv405nvUbt

Entry address:
0x11EC

Entry point:
68, D4, 9F, 58, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 3F, 32, 4F, 9D, 83, 77, 08, 49, A3, 98, BD, 33, 4C, 18, 8F, 15, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, C8, 0F, 72, 02, 76, 62, 34, 70, 72, 6F, 6A, 65, 63, 74, 56, 62, 00, 08, 41, 00, 00, 00, 00, 00, FF, CC, 31, 00, 1E, 8D, D7, 54, 82, 55, 5C, C6, 42, BD, 0A, 27, 7B, 6D, 16, 1C, 0C, EC, BD, 96, A0, 5B, AF, C3, 44, AB, C6, B3, 01, 48, F3, 87, D3, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
1.6 MB (1,630,208 bytes)

Scan setupv0.exe - Powered by Reason Core Security