inkscape.exe

The application inkscape.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.descarga-programas.com.
MD5:
786ee6befb4fa5c35fdc9ece7172afdf

SHA-1:
3681c28a5d9e1a9409fa65702d52f7ae60c948c0

SHA-256:
e72a949896b0e67a4736c1a4d5cad2c231b73815532b8d93f65cc3baaca52863

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 5:21:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore
16.7.19.3

File size:
1.1 MB (1,129,592 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\inkscape.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:nxGpi3Y1AOpfXOuCbQIb81xq/UmwrXesQkzbBvtK8I:nxGpq0YuJpM/VwbQkzbBv

Entry address:
0xC1DF0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 18, 4B, 40, 00, E8, 35, F5, FF, FF, AC, 71, 47, 00, 8B, C0, FF, 25, A8, 71, 47, 00, 8B, C0, FF, 25, A4, 71, 47, 00, 8B, C0, FF, 25, A0, 71, 47, 00, 8B, C0, FF, 25, 9C, 71, 47, 00, 8B, C0, FF, 25, 98, 71, 47, 00, 8B, C0, FF, 25, 94, 71, 47, 00, 8B, C0, FF, 25, 90, 71, 47, 00, 8B, C0, FF, 25, 8C, 71, 47, 00, 8B, C0, FF, 25, 88, 71, 47, 00, 8B, C0, FF, 25, 84, 71, 47, 00, 8B, C0, FF, 25, 80, 71, 47, 00, 8B, C0, FF, 25, EC, 71, 47, 00, 8B, C0, FF, 25, 7C, 71, 47, 00, 8B, C0, FF, 25...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
788 KB (806,912 bytes)

The file inkscape.exe has been seen being distributed by the following URL.

Remove inkscape.exe - Powered by Reason Core Security