popscan.exe

Sensational AG

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PopScan Scanner Reader’.
Publisher:
Sensational AG  (signed and verified)

MD5:
17d027ce49ba0165890262c4a1c07305

SHA-1:
c394f256ae55dc9308ec6129a8059518f9ccb649

SHA-256:
6ad425c4e300ef3540212ca78fc52c983036fd0bd2632a9b0f502404a52eb383

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/4/2025 7:09:53 AM UTC  (today)

File size:
4 MB (4,192,656 bytes)

File type:
Executable application (Win32 EXE)

Language:
Griechisch (Griechenland)

Common path:
C:\users\{user}\appdata\roaming\popscan\popscan.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/18/2013 1:00:00 AM

Valid to:
4/27/2016 2:00:00 PM

Subject:
CN=Sensational AG, O=Sensational AG, L=Zürich, C=CH

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A6773A2DAB82C8DBA2AD65C19C4B774

File PE Metadata
Compilation timestamp:
5/6/2015 9:40:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:MNtiASa3M4E+A7DPKYVNzxYai5gcyAKnuTqpRRQCup9T9AomAK5:MzX4Nzdi5jy5sppComAK

Entry address:
0x304298

Entry point:
55, 8B, EC, B9, 08, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 50, 64, 6F, 00, E8, 64, 73, D0, FF, 8B, 3D, 40, D2, 71, 00, 33, C0, 55, 68, CC, 44, 70, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, 33, C0, E8, C6, 03, D0, FF, 8B, 45, E8, 8D, 55, EC, E8, 8F, 1B, D1, FF, 8D, 45, EC, BA, E8, 44, 70, 00, E8, CE, 39, D0, FF, 8B, 45, EC, E8, EA, 70, DC, FF, 84, C0, 75, 2E, 8D, 55, E0, 33, C0, E8, 98, 03, D0, FF, 8B, 45, E0, 8D, 55, E4, E8, 61, 1B, D1, FF, 8D, 45, E4, BA, 0C, 45, 70, 00, E8, A0, 39, D0, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3 MB (3,158,528 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PopScan Scanner Reader

Command:
"C:\users\{user}\appdata\roaming\popscan\popscan.exe" \autostart


Scan popscan.exe - Powered by Reason Core Security