KeePass.exe

KeePass

Dominik Reichl

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KeePass 2 PreLoad’. The file has been seen being downloaded from doc-14-2k-docs.googleusercontent.com.
Publisher:
Dominik Reichl

Product:
KeePass

Version:
2.27.0.0

MD5:
e032ecb5304f71d642a977bc2c1c2b8e

SHA-1:
ab00616b1238a8384b1e065b0ceb0e12b362f1f6

SHA-256:
3b8ec8a70ee69adbdeeac3d9055d60c78e8ff774a6113dd4c6baafe09061c58e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 1:08:14 PM UTC  (today)

File size:
2 MB (2,117,632 bytes)

Product version:
2.27.0.0

Copyright:
Copyright © 2003-2014 Dominik Reichl

Original file name:
KeePass.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\keepass password safe 2\keepass.exe

File PE Metadata
Compilation timestamp:
7/6/2014 9:36:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:n/j62z6v8W+fuIICMzR1O4c/rNoUXI35:n+2+F1CMw

Entry address:
0x1F68DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2 MB (2,050,560 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KeePass 2 PreLoad

Command:
"C:\Program Files\keepass password safe 2\keepass.exe" --preload


The file KeePass.exe has been seen being distributed by the following URL.

Scan KeePass.exe - Powered by Reason Core Security