5963213_stp.exe

Free mp3 Wma Converter

Koyote-Lab Inc.

The application 5963213_stp.exe, “Free mp3 Wma Converter Install” by Koyote-Lab has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from r2.computerbild.de and multiple other hosts.
Publisher:
Koyote-Lab Inc  (signed by Koyote-Lab Inc.)

Product:
Free mp3 Wma Converter

Description:
Free mp3 Wma Converter Install

Version:
1.0.0.129862

MD5:
3ec9fc65542769f3d335c4b379dc99e5

SHA-1:
80227dde308bb11a588f56b42d420ee9cd92d886

SHA-256:
bd1731607c3b565547dd880960a55c91b50ea1faffebbe08e5fb255e64134e18

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/7/2024 6:06:59 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.KoyoteLab.L
14.2.16.3

File size:
1.1 MB (1,167,808 bytes)

Product version:
1.0.0.129862

Copyright:
Copyright (c) 2012

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\5963213_stp.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/23/2012 1:00:00 AM

Valid to:
2/22/2014 12:59:59 AM

Subject:
CN=Koyote-Lab Inc., OU=DEV, O=Koyote-Lab Inc., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7AD16C59E384A2E3D38D2287483F9B2B

File PE Metadata
Compilation timestamp:
5/30/2013 10:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:f0Vsm5s7BdjkcIP4F1XaiCm0kPREZlDHDgZYQv7E+Ny:2ps7BdArQF1XOm0kPRkGvXy

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file 5963213_stp.exe has been seen being distributed by the following 13 URLs.

Remove 5963213_stp.exe - Powered by Reason Core Security