_www.gigapurbalingga.com__kepm119temk.exe

Simple.Prod

Smart KOM, TOV

The application _www.gigapurbalingga.com__kepm119temk.exe by Smart KOM, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Simple.creation company   (signed by Smart KOM, TOV)

Product:
Simple.Prod

Description:
Getting apps

Version:
3.1.2.4

MD5:
c4c40e8d9462b197bcfb47fa597c8e17

SHA-1:
db02c6bcbc4e89e886d146637aa3464c17cc92dd

SHA-256:
06dba1e8b8b7f69c874ec7dcbd1b029b46a451c9b0cf753dd0f22aa79237a317

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 1:41:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.3.15.20

File size:
4.8 MB (5,059,760 bytes)

Product version:
2.5.2.19

Copyright:
Simple.All right reserved

Trademarks:
Simple.LegalTrademark

Original file name:
Simple.apps

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\_www.gigapurbalingga.com__kepm119temk.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/1/2016 7:00:00 AM

Valid to:
4/17/2017 6:59:59 AM

Subject:
CN="Smart KOM, TOV", OU=IT, O="Smart KOM, TOV", STREET="vul. Lvivska, 22", L=Kyiv, S=Kyiv, PostalCode=03115, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EE6BB0158E1CFBB0A2A756AD56D40B4F

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x27D678

Entry point:
55, 8B, EC, 83, C4, DC, 53, 56, 57, 33, C0, 89, 45, E0, 89, 45, E4, 89, 45, E8, 89, 45, EC, B8, 70, CA, 67, 00, E8, 97, A6, D8, FF, 33, C0, 55, 68, C4, DA, 67, 00, 64, FF, 30, 64, 89, 20, E8, B0, 5A, D8, FF, 33, C0, 55, 68, B4, D7, 67, 00, 64, FF, 30, 64, 89, 20, 83, 3D, 80, 9E, 75, 00, 00, 75, 07, 83, 3D, 7C, 9E, 75, 00, 00, 74, 4E, 33, C0, 55, 68, 10, D7, 67, 00, 64, FF, 30, 64, 89, 20, A1, 60, 1E, 75, 00, 29, 05, 60, 1E, 75, 00, 73, 05, E8, B4, 6B, D8, FF, 8D, 55, EC, A1, 60, 1E, 75, 00, E8, 5F, A4, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 MB (2,608,128 bytes)

Remove _www.gigapurbalingga.com__kepm119temk.exe - Powered by Reason Core Security