ki7997.exe

Kaspersky Security Scan

Kaspersky Lab

This is a setup program which is used to install the application. The file has been seen being downloaded from filehippo.com and multiple other hosts.
Publisher:
Лаборатория Касперского  (signed by Kaspersky Lab)

Product:
Kaspersky Security Scan

Description:
Kaspersky Security Scan [15.0.0.737.0.1.0]

Version:
15.0.0.737

MD5:
decb1ae96e1e91bd1b6e81b9c64d27d8

SHA-1:
73220e281f2a671d3ce68cbfc878b7e0542735a8

SHA-256:
897c94484873401644d8933354770ecdd23196533a5fb0049be3cc076bc35c1f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
8/6/2025 4:53:48 PM UTC  (today)

File size:
1.9 MB (1,988,928 bytes)

Product version:
15.0.0.737

Copyright:
© ЗАО "Лаборатория Касперского", 2015

Trademarks:
Зарегистрированные товарные знаки и знаки обслуживания являются собственностью их правообладателей.

Original file name:
Setup

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ki7997.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/22/2013 3:00:00 AM

Valid to:
4/28/2015 3:00:00 AM

Subject:
CN=Kaspersky Lab, O=Kaspersky Lab, L=Moscow, C=RU

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0226E6BDA76DAE711E3DB2321E3B5308

File PE Metadata
Compilation timestamp:
4/6/2015 3:49:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:qEy+uU2rhBzQIAZvE6zZg7dQ8ItKjdAjpOKOpgyrv9A2Og5IXKt:8ZdKBnIdQdFt1yzC2Og5x

Entry address:
0x3146

Entry point:
E8, 04, 17, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, BC, 40, 00, 89, 0D, 54, BC, 40, 00, 89, 15, 50, BC, 40, 00, 89, 1D, 4C, BC, 40, 00, 89, 35, 48, BC, 40, 00, 89, 3D, 44, BC, 40, 00, 66, 8C, 15, 70, BC, 40, 00, 66, 8C, 0D, 64, BC, 40, 00, 66, 8C, 1D, 40, BC, 40, 00, 66, 8C, 05, 3C, BC, 40, 00, 66, 8C, 25, 38, BC, 40, 00, 66, 8C, 2D, 34, BC, 40, 00, 9C, 8F, 05, 68, BC, 40, 00, 8B, 45, 00, A3, 5C, BC, 40, 00, 8B, 45, 04, A3, 60, BC, 40, 00, 8D, 45, 08, A3, 6C, BC, 40...
 
[+]

Code size:
24.5 KB (25,088 bytes)

The file ki7997.exe has been seen being distributed by the following 9 URLs.

http://filehippo.com/download/file/.../