mpk.exe

Refog Inc.

The application mpk.exe by Refog has been detected as a potentially unwanted program by 13 anti-malware scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
Publisher:
Refog Inc.  (signed and verified)

Version:
8.1.6.2087

MD5:
41831bc863dffc08ac7b97cb54a76374

SHA-1:
0a998a7bd340d9e5986ba70e4f7589cbbd078e81

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 4:03:58 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Hacktool.Win32.MIPKOEmployeeMonitor
4.0.3.1573

Comodo Security
UnclassifiedMalware
22358

ESET NOD32
Win32/Monitor.MIPKOEmployeeMonitor.AC potentially unsafe (variant)
9.11745

Fortinet FortiGate
W32/Keylogger.AC!tr
7/3/2015

McAfee
Artemis!41831BC863DF
5600.6716

Microsoft Security Essentials
MonitoringTool:Win32/RefogKeylogger
1.1.11701.0

nProtect
Abuse-Worry/W32.KeyLogger.1784120
15.06.05.01

Panda Antivirus
Trj/Chgt.D
15.07.03.02

Reason Heuristics
PUP.Refog (M)
15.7.3.2

Sophos
Refog Keylogger
4.98

Trend Micro House Call
TROJ_SPNV.01II14
7.2.184

Trend Micro
TROJ_SPNV.01II14
10.465.03

VIPRE Antivirus
Refog Inc.
40882

File size:
1.7 MB (1,784,120 bytes)

Product version:
8.1.6.2087

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/4/2013 1:00:00 AM

Valid to:
3/6/2016 12:59:59 AM

Subject:
CN=Refog Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Refog Inc., L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7FF3DAF8E8B0D4A05A226B85F1054E87

File PE Metadata
Compilation timestamp:
8/11/2014 12:05:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:pyxs3bNp5V5s699q3w5PEBPCVjkn+GNOU:Kq5p5Q6H8BPCyf

Entry address:
0x1000

Entry point:
68, 01, A0, 94, 00, E8, 01, 00, 00, 00, C3, C3, 5E, E5, 95, 3E, E1, B0, 37, B4, FB, 15, 58, 90, D2, 71, 39, D5, 2A, 6C, 3C, 4F, 92, 30, 3F, 6D, 9A, 63, 4F, 3A, F5, 9B, 23, 5B, 55, D6, 81, DA, 7A, 40, 1F, 12, 3D, 7C, FE, 9A, AD, A8, 85, 7A, E3, 42, 00, B6, 3E, 1F, 52, 05, 19, EE, 11, D4, F0, 2D, C2, 87, 68, AA, 25, 37, CC, E0, D2, 91, 57, 82, 8F, E7, C8, B2, 2F, 36, E0, D7, C1, 60, A5, 62, 71, E7, EC, 47, 45, 18, 8B, 88, 97, 6B, 25, B0, 47, 55, 1A, 88, 6D, E3, 33, DE, A8, 40, 1E, 3B, C4, 05, 15, 4F, 6B, D1...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4 MB (4,212,736 bytes)

Remove mpk.exe - Powered by Reason Core Security