samsung-kies.exe

The application samsung-kies.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdnus.ironcdn.com.
MD5:
cf107a156943cf2614ab5965911f2be5

SHA-1:
b5a20cc5d2657c5f487f27d52ff9bbdca80c0e80

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 3:14:25 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.53.112

ESET NOD32
Win32/InstallCore.AZ (variant)
10.7786

File size:
1.1 MB (1,199,496 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\alain tanugi\mes documents\downloads\samsung-kies.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:PfUvMbHrpoNFDSVqu9nIEwWfgddaAbyOUntlqZF:PfUvW1bwenIEwWfCHyOU3A

Entry address:
0xD5A90

Entry point:
55, 8B, EC, 83, C4, F0, B8, BC, A1, 40, 00, E8, C1, E0, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
866 KB (886,784 bytes)

The file samsung-kies.exe has been seen being distributed by the following URL.

Remove samsung-kies.exe - Powered by Reason Core Security