mpkview.exe

Refog Inc.

The application mpkview.exe, “REFOG Monitoring Software” by Refog has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Refog Inc.  (signed and verified)

Description:
REFOG Monitoring Software

Version:
6.2.2.1107

MD5:
d19da8237d25b81cac0a7760bca3b30e

SHA-1:
0ede24f7cebbe852246a63857f213995cd0cac3b

SHA-256:
b023e3636581d523ed20e5f67261fb6c424e3114dc85aed02909645cb6e44445

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 10:44:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.30.9

File size:
2.8 MB (2,907,472 bytes)

Product version:
6.2.2.1107

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\mpk\mpkview.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/5/2010 8:00:00 PM

Valid to:
2/6/2012 7:59:59 PM

Subject:
CN=Refog Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Refog Inc., L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2C65F10795394990A2209CE7972CFBAC

File PE Metadata
Compilation timestamp:
8/31/2010 3:45:43 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:cZLg5JJqnLfBoHAYga94mEMscMSImAjnXFZeS0zzUYo3FxME970cOU7m6alnSO:cZLyKuKa9459qIdVZv0HuxrVOU7alJ

Entry address:
0x1000

Entry point:
68, 01, 50, AD, 00, E8, 01, 00, 00, 00, C3, C3, DB, 8E, 4E, 80, 1A, 6E, 94, 54, DE, 74, 28, B1, CA, FE, BB, 46, 36, 5D, 4B, B1, EB, 0A, 33, D6, 23, 4E, 0A, 9F, F3, BB, A6, 8A, 70, 0F, 09, 3E, B1, CF, 22, BE, 4E, 3E, 61, F8, 6E, 20, 8D, 59, 0A, 16, 7D, 92, 58, 47, 7D, 65, 8A, 80, 3A, A1, A3, 22, 71, C2, 76, 2B, AB, 15, 08, 02, 5C, A5, 48, 70, CF, 92, E3, C5, 07, 71, 2E, C9, C9, 1B, 23, 8D, 2C, F1, 79, D5, 16, 0E, 95, CC, 01, 62, 74, 4B, 79, F2, 94, 3C, 98, 4E, A5, 24, 8F, 27, 11, A5, F2, 22, A8, 6B, 76, 31...
 
[+]

Entropy:
7.7429

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4.5 MB (4,736,512 bytes)

Windows Firewall Allowed Program
Name:
tcp\ip


Remove mpkview.exe - Powered by Reason Core Security