transpruszkow.exe

PUH

This is a setup program which is used to install the application. The file has been seen being downloaded from podgik.powiat.pruszkow.pl.
Publisher:
GEO-SYSTEM Sp. z o.o.  (signed by PUH )

Description:
Program Transfromacji Współrzędnych

Version:
2013.04.18.1

MD5:
3e615b11ba41a05f288bddee42216c9e

SHA-1:
de9220b405bb3bc79c60d8fdc8a56d75c076a307

SHA-256:
9a6a74e9037dabd53f6f3a849f57886de6a2ee7a7e3c1e46a71bbf1fce841758

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 8:53:18 PM UTC  (today)

File size:
3.7 MB (3,871,112 bytes)

Copyright:
GEO-SYSTEM Sp. z o.o. © 2013

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\transpruszkow.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
5/21/2013 7:33:08 AM

Valid to:
5/21/2014 7:33:08 AM

Subject:
E=geo-system@geo-system.com.pl, CN=Piotr JURCZAK, O="PUH ""GEO-SYSTEM"" sp. z o.o.", C=PL

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
700E28114A9AADC8F840E90A719165E8

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:iqfMNdnTUZCw5zuzv2BtWnm1lVK7xSZsgQYNw7M4Ef:iqfMQuDXelVsasbI//

Entry address:
0x773D8

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, A8, 71, 47, 00, E8, A7, F1, F8, FF, 8B, 1D, 8C, CA, 47, 00, 8B, 03, E8, FE, 83, FE, FF, 8B, 03, BA, 50, 74, 47, 00, E8, 02, 80, FE, FF, 8B, 0D, 9C, C8, 47, 00, 8B, 03, 8B, 15, 74, 3E, 47, 00, E8, F7, 83, FE, FF, 8B, 0D, 20, CB, 47, 00, 8B, 03, 8B, 15, CC, 39, 47, 00, E8, E4, 83, FE, FF, 8B, 0D, 28, CC, 47, 00, 8B, 03, 8B, 15, D4, 3B, 47, 00, E8, D1, 83, FE, FF, 8B, 03, E8, 4A, 84, FE, FF, 5B, E8, 1C, D2, F8, FF, FF, FF, FF, FF, 23, 00, 00, 00, 50, 72, 6F, 67, 72, 61, 6D, 20...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
473.5 KB (484,864 bytes)

The file transpruszkow.exe has been seen being distributed by the following URL.

Scan transpruszkow.exe - Powered by Reason Core Security