hppiw.exe

HP Webpack

Hewlett Packard

This is a setup program which is used to install the application. The file has been seen being downloaded from h30437.www3.hp.com and multiple other hosts.
Publisher:
Hewlett-Packard Company  (signed by Hewlett Packard)

Product:
HP Webpack

Version:
1.0

MD5:
9d0db3c69076a2a00f08829f88d668d6

SHA-1:
041e7c1025808734ff7bfac09aacdad6d9739d3c

SHA-256:
fafce6ee0f7f3dd8f53f317c2ca683877194866ef0f0dffd9cb21e048a48c3c4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:40:30 PM UTC  (today)

File size:
2.4 MB (2,474,920 bytes)

Product version:
1.0

Copyright:
Hewlett-Packard Company

Original file name:
7zS.sfx

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\hppiw.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/2/2015 1:00:00 AM

Valid to:
10/2/2016 12:59:59 AM

Subject:
CN=Hewlett Packard, OU=Desktop Consumer Solutions, O=Hewlett Packard, L=San Diego, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2738025E0F7AA4439C70822BAA8CE7B1

File PE Metadata
Compilation timestamp:
9/27/2010 11:34:01 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:utXMCmhk72vA21FyexoC7y9Pbh2F/GyU2+PtT0iiFayz+IIHEchIS1SSAuvT:upMriaAOFRytbADE0/tSIijZZL

Entry address:
0x1C78D

Entry point:
E8, CE, 56, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 48, DF, 42, 00, E8, ED, 27, 00, 00, 6A, 0E, E8, ED, 1C, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, F0, 26, 43, 00, BA, EC, 26, 43, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 89, EB, FF, FF, 59, FF, 76, 04, E8, 80, EB, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, DC, 27, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, B8, 1B, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.9486  (probably packed)

Code size:
151.5 KB (155,136 bytes)

The file hppiw.exe has been seen being distributed by the following 50 URLs.

http://h30437.www3.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=ko&h_client=s-h-e019-1&h_keyword=dg-PIW

http://members.driverguide.com/.../dispatch_cache_get.php?msl=9d0db3c69076a2a00f08829f88d668d6,1984676_1469793262&time=1480960555&auth=b036046f0054355fb161b29c4c3f7fd2&file=hppiw.exe

http://h20180.www2.hp.com/apps/.../BlackMagic

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=tr&h_client=s-h-e019-1&h_keyword=dg-PIW

http://h30638.www3.hp.com/pub/softlib/software12/COL50403/.../hppiw.exe

http://whp-aus1.cold.extweb.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=fr&h_client=s-h-e005-01&h_keyword=dg-PIW

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=de&h_client=s-h-e019-1&h_keyword=dg-PIW

http://whp-hou9.cold.extweb.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

http://www.hpwindows10.com/goto/Download/.../1

http://gadgetube.digidip.net/visit?url=http://ftp.hp.com/pub/printers/hppiw/hppiw.exe&ref=531_30_49654x304x&ppref=http://gadgetube.net

http://whp-aus1.cold.extweb.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

https://www.google.com/url?hl=ru&q=http://ftp.hp.com/pub/printers/.../hppiw.exe&source=gmail&ust=1470161779370000&usg=AFQjCNF3BAyIt10ynOfcuAyXRQ3JN5E0YA

http://whp-aus2.cold.extweb.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

http://h20180.www2.hp.com/apps/.../BlackMagic

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=nl&h_client=s-h-e019-1&h_keyword=dg-PIW

http://h30438.www3.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=en&h_keyword=dg-PIW

http://h20180.www2.hp.com/apps/Nav?h_pagetype=s-926&h_lang=it&h_client=s-h-e019-1&h_keyword=dg-PIW&jumpid=ex_r4155/it/hho/ipg/Krnk/.../

http://h20565.www2.hp.com/hpsc/swd/.../obtainSoftware?url=687474703A2F2F6674702E68702E636F6D2F7075622F736F66746C69622F736F66747761726531332F434F4C35303430332F6D702D3135303538302D322F68707069772E657865

http://ftp.hp.com/pub/printers/.../HPPSdr.exe

http://whp-aus2.cold.extweb.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

http://h20180.www2.hp.com/.../Nav?h_pagetype=s-926&h_lang=ar&h_client=s-h-e005-01&h_keyword=dg-PIW

http://whp-hou4.cold.extweb.hp.com/pub/softlib/software13/COL50403/.../hppiw.exe

temp:hppiw.exe

Latest 30 of 73 download URLs