lekirefundowane1.2.exe

Monika Andrzejak

This is a setup program which is used to install the application. The file has been seen being downloaded from www.pharmlex.pl.
Publisher:
Monika Andrzejak  (signed and verified)

Version:
1.1.0.0

MD5:
d2637f47bce3f3b8c6e2e50522992c32

SHA-1:
47b409acbfe904711361eb6f8f0bacc3201aa9aa

SHA-256:
f87be8e3f70e601125391476863df883b96641d6e69da406d99844e2846b88f4

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/19/2024 7:22:22 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
TrojWare.Win32.Injector.ATIU
17670

File size:
9.4 MB (9,906,096 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Polish (Poland)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2014 1:00:00 AM

Valid to:
1/12/2015 12:59:59 AM

Subject:
CN=Monika Andrzejak, O=Monika Andrzejak, STREET=Heroldow 10-16, L=Warszawa, S=Mazowieckie, PostalCode=01991, C=PL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4AC1A9458DCCE22AC3D0781632010D94

File PE Metadata
Compilation timestamp:
1/3/2014 8:18:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:kX9ZRcV2ROmdHLrzx58B4DZwgYEDpeTTtnIGKlypp6LzValy3:kX9ZKVk9X/8AwgNtefHKlypp6f

Entry address:
0x2911C4

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, 88, 5A, 68, 00, E8, 07, D2, D7, FF, 33, C0, 55, 68, 4D, 13, 69, 00, 64, FF, 30, 64, 89, 20, A1, A0, DB, 69, 00, 66, C7, 80, C2, 00, 00, 00, 2E, 00, 68, 5C, 13, 69, 00, 68, 80, 13, 69, 00, E8, 80, 14, D8, FF, A3, 28, 3A, 6A, 00, 83, 3D, 28, 3A, 6A, 00, 00, 75, 14, 68, 90, 13, 69, 00, 68, 80, 13, 69, 00, E8, 63, 14, D8, FF, A3, 28, 3A, 6A, 00, 83, 3D, 28, 3A, 6A, 00, 00, 0F, 85, F9, 00, 00, 00, A1, F4, D9, 69, 00, 8B, 00, E8, FD, C3, F3, FF, 8D, 55, EC, B8, 1A...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.6 MB (2,688,512 bytes)

The file lekirefundowane1.2.exe has been seen being distributed by the following URL.

http://www.pharmlex.pl/LekiRefundowane1.2.exe

Scan lekirefundowane1.2.exe - Powered by Reason Core Security