kill_ping_0.0.32.12+(64x).exe

GZ Systems Limited

The application kill_ping_0.0.32.12+(64x).exe, “Kill Ping Setup ” by GZ Systems Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from killping.com.
Publisher:
Kill Ping   (signed by GZ Systems Limited)

Product:
Kill Ping

Description:
Kill Ping Setup

MD5:
529b4688afffb4725bc1364fbbcc0275

SHA-1:
2e312843a7a37108b560ac592a90978825fdbca6

SHA-256:
7c69398df85700b04d907315bd2a4268ec37ceee446991646dbc202adaebd472

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 3:24:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.2.11.16

File size:
6.5 MB (6,801,240 bytes)

Product version:
0.0.32.12

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\kill_ping_0.0.32.12+(64x).exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/13/2014 8:00:00 AM

Valid to:
7/19/2017 8:00:00 PM

Subject:
CN=GZ Systems Limited, O=GZ Systems Limited, L=Central, C=HK

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A2CCAF4D3DD3C728B1DB1355CE5FDAC

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9615

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file kill_ping_0.0.32.12+(64x).exe has been seen being distributed by the following URL.

http://killping.com/.../windows

Remove kill_ping_0.0.32.12+(64x).exe - Powered by Reason Core Security