{blocked}.exe

Hot Keyboard Pro

Imposant

The application {blocked}.exe, “Hot Keyboard Pro Setup ” by Imposant has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from hot-keyboard.com.
Publisher:
Imposant   (signed by Imposant)

Product:
Hot Keyboard Pro

Description:
Hot Keyboard Pro Setup

MD5:
dcc09effcab904758debec4366a98653

SHA-1:
3f289fc355fd01ecbfe1ffedb917ef7c8b890595

SHA-256:
255aacd7a6fe48ef27fc127d6af92f2352f8519c6dcb857619fcdf6c28e5abe1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 5:19:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.30.18

File size:
2.8 MB (2,904,800 bytes)

Product version:
5.1

Copyright:
Copyright (c) 1998-2014 Imposant

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hot-keyboard-5.3.81.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/21/2012 8:00:00 PM

Valid to:
8/22/2017 7:59:59 PM

Subject:
CN=Imposant, O=Imposant, STREET="17-76, Olimpiyskaya derevnya", STREET=Michurinsky prospekt, L=Moscow, S=Moscow, PostalCode=119602, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00AB35D8BB16D774993034FF77BDA941AD

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9970

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file {blocked}.exe has been seen being distributed by the following URL.

http://hot-keyboard.com/.../hot-keyboard-5.3.81.exe

Remove {blocked}.exe - Powered by Reason Core Security