rkping.exe

ngpInc

The application rkping.exe by ngpInc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
ngpInc  (signed and verified)

MD5:
1fb62f23178f9b649159c3c5196ce705

SHA-1:
5796adb457b58496ca7d3bb0a9cc5f8641e2cda4

SHA-256:
5178b314344ab2b24ec96bab6cfbaaae6eedc69c063e7fdee5e091c1f47bb2db

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 4:50:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ngpInc (M)
16.2.29.17

File size:
571.9 KB (585,664 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\realkeyword\rkping.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/25/2012 9:00:00 AM

Valid to:
12/25/2014 8:59:59 AM

Subject:
CN=ngpInc, OU=Dev. Team, O=ngpInc, L=Buchun-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2FE908284F80DB9341F25E7D2FC1CF9F

File PE Metadata
Compilation timestamp:
8/10/2012 4:59:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:4aBjrRG/hHxwnf/0B09kiBxevckUmxNPJ+U:4bhHGf8O9kdWc

Entry address:
0x330C7

Entry point:
E9, B4, 63, 00, 00, E9, 9F, EF, 01, 00, E9, CA, E7, 05, 00, E9, 15, A6, 03, 00, E9, 70, F6, 04, 00, E9, 1B, 74, 04, 00, E9, 46, 2E, 06, 00, E9, B1, 59, 02, 00, E9, 26, 2C, 06, 00, E9, 97, AC, 01, 00, E9, 62, A1, 00, 00, E9, 0D, 2D, 01, 00, E9, F8, F5, 04, 00, E9, E3, 85, 04, 00, E9, FA, 2D, 06, 00, E9, E9, 07, 06, 00, E9, 04, A6, 03, 00, E9, 6F, 5C, 02, 00, E9, DA, FA, 02, 00, E9, 21, 2D, 06, 00, E9, 90, 86, 00, 00, E9, FB, 7D, 04, 00, E9, 56, CA, 04, 00, E9, 71, 7C, 04, 00, E9, 7A, 2D, 06, 00, E9, 47, C2...
 
[+]

Entropy:
5.4478

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
412 KB (421,888 bytes)

Remove rkping.exe - Powered by Reason Core Security