upd-ps-x64-6.0.0.18849.exe

Hewlett-Packard Company

This is a setup program which is used to install the application. The file has been seen being downloaded from d3.driver.ru and multiple other hosts.
Publisher:
Hewlett-Packard Company  (signed and verified)

MD5:
b477a084884194e6c3cd2e09d8c69ea6

SHA-1:
95877637fdba4e91b22c8cf0e54346119bd84d5c

SHA-256:
2c8bc2ac1cfd4cfd19427bcb25c1e269195d0752aa29af836d4ef369ea18b329

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:07:52 PM UTC  (today)

File size:
19.3 MB (20,257,008 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hp cp1518ni drivers software firmware\drivers\upd-ps-x64-6.0.0.18849.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/24/2014 7:00:00 PM

Valid to:
7/24/2016 6:59:59 PM

Subject:
CN=Hewlett-Packard Company, O=Hewlett-Packard Company, L=Palo Alto, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3FD0E01189629482B464D5D9FD033B30

File PE Metadata
Compilation timestamp:
11/2/2009 2:23:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
393216:M8NH+GKWXe/k0vtTPm0whcxytO19RxzUr6gkFOj6m3VYePVdmnANei2:dH+GKYOhmyLbc44V/PVQAwi2

Entry address:
0xA79E

Entry point:
E8, 6E, 4A, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 20, 3C, 42, 00, 89, 0D, 1C, 3C, 42, 00, 89, 15, 18, 3C, 42, 00, 89, 1D, 14, 3C, 42, 00, 89, 35, 10, 3C, 42, 00, 89, 3D, 0C, 3C, 42, 00, 66, 8C, 15, 38, 3C, 42, 00, 66, 8C, 0D, 2C, 3C, 42, 00, 66, 8C, 1D, 08, 3C, 42, 00, 66, 8C, 05, 04, 3C, 42, 00, 66, 8C, 25, 00, 3C, 42, 00, 66, 8C, 2D, FC, 3B, 42, 00, 9C, 8F, 05, 30, 3C, 42, 00, 8B, 45, 00, A3, 24, 3C, 42, 00, 8B, 45, 04, A3, 28, 3C, 42, 00, 8D, 45, 08, A3, 34, 3C, 42, 00, 8B...
 
[+]

Entropy:
7.9990  (probably packed)

Code size:
72 KB (73,728 bytes)

The file upd-ps-x64-6.0.0.18849.exe has been seen being distributed by the following 22 URLs.

https://d3.driver.ru/1247ac915425386f/2d03a361452a584d10c24113e7995b8ff976be6104d7efe97d652adacbc25d55c4a4987f0e0c5fb002f19feb8d459d255886c21d/4/80/10/.../upd-ps-x64-6.0.0.18849.exe

https://d3.driverscollection.com/1247ac8874f8850c/5331546f66efa3704f3196fd97ec279ce66e8df748ef11acfaecd9c3bdce1e1b91e8d795ac85a31eb60dd254849a7e6057d6da24/4/80/10/.../upd-ps-x64-6.0.0.18849.exe

https://d3.driverscollection.com/1b015bb89cf21a0/24c64eaea952c5b87407045d60bb7a5f185076b65733249c6931bb0bb3ebea2e2480ee44e2be835c780f7728aa7006fd57f5c996/4/80/10/.../upd-ps-x64-6.0.0.18849.exe

https://d3.driverscollection.com/1247ac9e587614be/6cf68fac6bb82014f5c845e8661b9026037a547638fdd1ddcbee4251902620b6cac1b68b36ca30d27191f1858e42724055d43920/4/80/10/.../upd-ps-x64-6.0.0.18849.exe

https://d3.driverscollection.com/6e854c45b7fb/cd295a8a95a18d8dc847119ae5aa9e96d0a9bc082c4d474211f43c6b201e76284717707bd8c1cf72a37622b90bf1bf1255f9647a/4/80/10/.../upd-ps-x64-6.0.0.18849.exe

https://d3.driverscollection.com/_7_14182132182222272322a01e358b05f960cbaf8ef32773655/de3c5f12e879903f4193ed3fc89f3fd4e5a9eafce6d341caeebb0b0df68912aefb702a2198c6c12bac9ab00ddea7316957a6463f/4/80/10/.../upd-ps-x64-6.0.0.18849.exe