mcpr.exe

McAfee ESD Package

McAfee, Inc.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from tomshardware.digidip.net and multiple other hosts.
Publisher:
McAfee, Inc.  (signed and verified)

Product:
McAfee ESD Package

Version:
7.6

MD5:
d014d9560cd7db184c01bae53e766c1a

SHA-1:
d43570c653a512585026b087d53d84ea5e782ddb

SHA-256:
f291eaf4b561c80a63346db6e38e8dac6a7f3b51d4e65893a377d24e68ad6143

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 6:47:58 AM UTC  (today)

File size:
3.3 MB (3,480,040 bytes)

Product version:
7.6.133.0

Copyright:
Copyright © 2010 McAfee, Inc

Original file name:
coreESD.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mcpr.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/6/2011 2:00:00 AM

Valid to:
10/9/2014 1:59:59 AM

Subject:
CN="McAfee, Inc.", OU=IIS, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="McAfee, Inc.", L=Santa Clara, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F99DF0A80729A4B7CB75C1C7E4B473D

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:DWnUy7C2U7q702ep2SlXLzFqEXMxOqEZ1lcWHsjEViKYLuTMLzspuhzm3l0aTmLZ:DW3WheO7nnMIZ1lVVF9uBShTfgC9ieqh

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8509

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file mcpr.exe has been seen being distributed by the following 50 URLs.

http://tomshardware.digidip.net/visit?url=http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe&ppref=https://.../

http://support-emc.services.bitdefender.com/track/click/.../download.mcafee.com?p=eyJzIjoiQV9rekFGZEF4Y2E2S0I3UkRwTkYyQ05iMFZ3IiwidiI6MSwicCI6IntcInVcIjozMDI3MDk1NCxcInZcIjoxLFwidXJsXCI6XCJodHRwOlxcXC9cXFwvZG93bmxvYWQubWNhZmVlLmNvbVxcXC9wcm9kdWN0c1xcXC9saWNlbnNlZFxcXC9jdXN0X3N1cHBvcnRfcGF0Y2hlc1xcXC9NQ1BSLmV4ZVwiLFwiaWRcIjpcImY5MDlkYjIwNTZkNDQ5ODNiNmVmODE4NTM0NjhmNGU2XCIsXCJ1cmxfaWRzXCI6W1wiOWYyZjUzOGNkNzNiMjJmOWM3MjI2NTI4N2I4ZDgzNDgzNjU0YWUwZlwiXX0ifQ

http://l.facebook.com/l.php?u=http://download.mcafee.com/products/licensed/.../MCPR.exe&h=BAQH45W8V

http://srwtck.com/get?key=b11e8793cade0a4fedc9f17323b20200&ref=http://www.bleepingcomputer.com/download/mcafee-consumer-products-removal-tool/dl/51/&uid=72934839&out=http://download.mcafee.com/products/licensed/.../MCPR.exe

http://redirect.viglink.com/?format=go&jsonp=vglnk_147889839369014&key=25a82360096c162c6f7ee41205eee498&libId=ive9w2j001001il7000DAe590ht6j&loc=http://www.pchell.com/virus/uninstallmcafee.shtml&v=1&out=http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe&ref=https://www.google.com.co/&title=PC Infierno: Cómo desinstalar McAfee&txt=<font><font class="">http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe</.../font><br> <br>

http://redirect.viglink.com/?format=go&jsonp=vglnk_148294045427512&key=25a82360096c162c6f7ee41205eee498&libId=ix94dxe901001il7000DA4n6n8fny&loc=http://www.pchell.com/virus/uninstallmcafee.shtml&v=1&out=http://download.mcafee.com/products/licensed/.../MCPR.exe&ref=https://www.google.co.in/&title=PC Hell: How to Uninstall McAfee&txt=http://download.mcafee.com/products/licensed/.../MCPR.exe<br> <br>

http://www.techtudo.com.br/_/software/.../download

http://download.mcafee.com/products/licensed/.../McPreInstall.exe

https://www.google.com/url?hl=de&q=http://download.mcafee.com/products/licensed/.../MCPR.exe&source=gmail&ust=1477744395337000&usg=AFQjCNFBsVMCvmwyOJug-n4esu9QAtHWDw

http://www.mrtab.notlong.com/

http://jump.bdimg.com/safecheck/.../H9DHu6FD0Wi90JdQltYQzXglnKDfXVl0StgAy51Bo7QEbPaO VTcuoRQgoEwTOurqCrgk5E6 AVZHHfzHiYqUKbsJkpFloKZcZvvMcnEc2Lc0bjOTaKgXdmEFX3ZMCahZXTMDxm7iZ2BjQ=

http://dc314.4shared.com/download/.../MCPR.exe

http://url.qso4you.com/30c

http://www.techspot.com/downloads/downloadnow/.../?evp=edb2ed37deb36891a0c0bc2ade110514&file=1

http://support-emc.services.bitdefender.com/track/click/.../download.mcafee.com?p=eyJzIjoiZ1dCVEhQanYzOUIxU3ZOMktqdEk0YWZvUXJRIiwidiI6MSwicCI6IntcInVcIjozMDI3MDk1NCxcInZcIjoxLFwidXJsXCI6XCJodHRwOlxcXC9cXFwvZG93bmxvYWQubWNhZmVlLmNvbVxcXC9wcm9kdWN0c1xcXC9saWNlbnNlZFxcXC9jdXN0X3N1cHBvcnRfcGF0Y2hlc1xcXC9NQ1BSLmV4ZVwiLFwiaWRcIjpcIjM3MTBjMzVmMjVlOTQ0MDlhNzJlMTU5YTYzOTgwYzg0XCIsXCJ1cmxfaWRzXCI6W1wiOWYyZjUzOGNkNzNiMjJmOWM3MjI2NTI4N2I4ZDgzNDgzNjU0YWUwZlwiXX0ifQ

https://mega.nz/temporary/.../e5F0CTTI

ftp://172.30.30.11/Antivirus Software/.../MCPR.exe

http://ishu:2987/transfer/.../MCPR.exe

Latest 30 of 53 download URLs

Scan mcpr.exe - Powered by Reason Core Security