gps7s64.exe

GPSDirect Sensor Driver

MICHAEL CHOURDAKIS

This is a setup program which is used to install the application. The file has been seen being downloaded from www.turboirc.com and multiple other hosts.
Publisher:
TurboIRC.COM  (signed by MICHAEL CHOURDAKIS)

Product:
GPSDirect Sensor Driver

Version:
1.Win32.Win64

MD5:
2713c5c181d5090d331de69863c19db5

SHA-1:
9f984f07ee75e32eb181609f1f8e77b3a3a472ae

SHA-256:
b7c71085ea6ade367f6f6e6e4da8c484ea86ffd654d2f353dafde79e340a7c60

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 3:23:42 AM UTC  (today)

File size:
2.8 MB (2,942,640 bytes)

Product version:
1

Copyright:
Chourdakis G.Michael - TurboIRC.COM

Original file name:
GPS7SXX.EXE

File type:
Executable application (Win64 EXE)

Language:
Greek (Greece)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/27/2014 1:00:00 AM

Valid to:
3/27/2017 1:59:59 AM

Subject:
CN=MICHAEL CHOURDAKIS, O=MICHAEL CHOURDAKIS, STREET=AGIAS PARASKEYIS 61, L=PIRAEUS, S=GREECE, PostalCode=18539, C=GR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7FB71E0CCD2B7F3D76B0E838C81B4A18

File PE Metadata
Compilation timestamp:
2/15/2015 11:01:14 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:6afE6vJzxedrFJ1BZ1LUc/NunLFv4MrER6aEBNnS8dRenCUA7Qig:NfVvJAhFzBZlUc4FHU6BBNbRAA71g

Entry address:
0x207F8

Entry point:
48, 83, EC, 28, E8, 3F, BD, 00, 00, 48, 83, C4, 28, E9, 02, 00, 00, 00, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 30, E8, A0, 46, 00, 00, 0F, B7, F0, B9, 02, 00, 00, 00, E8, CB, BC, 00, 00, B8, 4D, 5A, 00, 00, 48, 8D, 3D, C7, F7, FD, FF, 66, 39, 05, C0, F7, FD, FF, 74, 04, 33, DB, EB, 31, 48, 63, 05, EF, F7, FD, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 75, EA, B9, 0B, 02, 00, 00, 66, 39, 48, 18, 75, DF, 33, DB, 83, B8, 84, 00, 00, 00, 0E, 76, 09, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89...
 
[+]

Code size:
334.5 KB (342,528 bytes)

The file gps7s64.exe has been seen being distributed by the following 2 URLs.

Scan gps7s64.exe - Powered by Reason Core Security