cp028709.exe

Online ROM Flash Component for Windows (x64) - Smart Array H240ar, H240nr, H240, H241, H244br, P240nr, P244br, P246br, P440ar, P440, P441, P542D, P741

Hewlett-Packard Company

This is a setup program which is used to install the application. The file has been seen being downloaded from h20564.www2.hpe.com.
Publisher:
Hewlett Packard Enterprise Development LP  (signed by Hewlett-Packard Company)

Product:
Online ROM Flash Component for Windows (x64) - Smart Array H240ar, H240nr, H240, H241, H244br, P240nr, P244br, P246br, P440ar, P440, P441, P542D, P741

Description:
Online ROM Flash Component for Windows (x64) - Smart Array H240ar, H240nr, H240, H241, H244br, P240nr, P244br, P246br, P440ar, P440, P441, P542D, P741m, P840, P840ar, and P841 Package

Version:
3.56

MD5:
db8e32127a7a1683f01abef944006c41

SHA-1:
69f2025cfe6499bfb126c31f47d965c10da62dc0

SHA-256:
2215efb9c1f0935a962b9c73312329bf6d8f6e247fa92596abc0cc1129e4d20b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 1:30:19 PM UTC  (today)

File size:
6.3 MB (6,644,616 bytes)

Product version:
3.56

Copyright:
© 1999, 2015 Hewlett Packard Enterprise Development LP

Original file name:
cpqstub.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\cp028709.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/10/2013 1:00:00 AM

Valid to:
6/9/2016 12:59:59 AM

Subject:
CN=Hewlett-Packard Company, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Hewlett-Packard Company, L=Andover, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D05F6CF73804309E0FEFFC950F584A5

File PE Metadata
Compilation timestamp:
9/17/2015 4:14:31 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
196608:3oIdAGuwWLNLIi9jWUPjJrR45qg2eG87NoFxZxt1/6M:xbuZJLIYWKjn45qxeG84tx6M

Entry address:
0x20960

Entry point:
48, 83, EC, 28, E8, 03, AE, 00, 00, 48, 83, C4, 28, E9, 72, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, 83, 64, 24, 40, 00, 4C, 8D, 44, 24, 40, E8, 63, AF, 00, 00, 48, 8B, D8, 48, 85, C0, 75, 1B, 39, 44, 24, 40, 74, 15, E8, 44, 3E, 00, 00, 48, 85, C0, 74, 0B, E8, 3A, 3E, 00, 00, 8B, 4C, 24, 40, 89, 08, 48, 8B, C3, 48, 83, C4, 20, 5B, C3, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 41, 55, 41, 57, 48, 83, EC, 40, 48, 8B, FA, 4C, 63, E1, 45, 33, FF, 4C, 89, 78, 10, 41, 8B...
 
[+]

Code size:
195.5 KB (200,192 bytes)

The file cp028709.exe has been seen being distributed by the following URL.