popscan.exe

Sensational AG

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PopScan Scanner Reader’.
Publisher:
Sensational AG  (signed and verified)

MD5:
36555bdd0bed6afca3ce40fb44eb987d

SHA-1:
8a3de5de8cb0f7716103425e86bb21bf84f4757e

SHA-256:
dc2a00ccf82804b4343c8d4bd96ef7eb60cb89e7fc2d994347f5b1dea83e558f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/4/2025 2:24:57 AM UTC  (today)

File size:
4.6 MB (4,871,976 bytes)

File type:
Executable application (Win32 EXE)

Language:
Griechisch (Griechenland)

Common path:
C:\users\{user}\appdata\roaming\popscan\popscan.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/11/2016 1:00:00 AM

Valid to:
2/15/2019 1:00:00 PM

Subject:
CN=Sensational AG, OU=PopScan, O=Sensational AG, L=Zürich, S=Zurich, C=CH

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0358C1DAE3F402669407EB7AFEF55E52

File PE Metadata
Compilation timestamp:
11/17/2016 10:41:45 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:uNtiASa3M4E+A7DPKYVNzxYai5gcyAKnuTqpRRQTJ9TU72W8mUc8:uzX4Nzdi5jy5MJp

Entry address:
0x304298

Entry point:
55, 8B, EC, B9, 08, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, C0, 64, 6F, 00, E8, 64, 73, D0, FF, 8B, 3D, 40, D2, 71, 00, 33, C0, 55, 68, CC, 44, 70, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, 33, C0, E8, C6, 03, D0, FF, 8B, 45, E8, 8D, 55, EC, E8, 8F, 1B, D1, FF, 8D, 45, EC, BA, E8, 44, 70, 00, E8, CE, 39, D0, FF, 8B, 45, EC, E8, EA, 70, DC, FF, 84, C0, 75, 2E, 8D, 55, E0, 33, C0, E8, 98, 03, D0, FF, 8B, 45, E0, 8D, 55, E4, E8, 61, 1B, D1, FF, 8D, 45, E4, BA, 0C, 45, 70, 00, E8, A0, 39, D0, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3 MB (3,158,528 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PopScan Scanner Reader

Command:
"C:\users\{user}\appdata\roaming\popscan\popscan.exe" \autostart


Scan popscan.exe - Powered by Reason Core Security