webplugin.exe

webplugin

Lupus-Electronics GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from nvr.lupus-ddns.de.
Publisher:
Lupus-Electronics GmbH  (signed and verified)

Product:
webplugin

Version:
3, 1, 0, 282553

MD5:
7fbb6411393020c5ef82f5c5be8e1d97

SHA-1:
1cfce34b3988bebce4611720910a44f42d2b39fc

SHA-256:
fe2492f490f572e72c74e001d6797a2ed7e4eb3088f24f0ade9117c04f3b7e05

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/29/2024 7:03:06 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/SilentInstall.A potentially unwanted application
6.3.12010.0

File size:
948.1 KB (970,832 bytes)

Product version:
3, 1, 0, 282553

Copyright:
Copyright 282553

Original file name:
webplugin.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\webplugin.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/23/2016 1:00:00 AM

Valid to:
8/23/2016 1:59:59 AM

Subject:
CN=Lupus-Electronics GmbH, O=Lupus-Electronics GmbH, L=Landau, S=Rheinland-Pfalz, C=DE

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
07E7BA1F60AA85E3239BD168FB007169

File PE Metadata
Compilation timestamp:
7/16/2015 1:39:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:WcptRzj2QNqKNwKS3nGKrJ+BjbPP43WeO1m1BJPJ1QDtJ:WcFz8KNdQ6CWRMJWD

Entry address:
0x8286

Entry point:
55, 8B, EC, 6A, FF, 68, 40, 93, 40, 00, 68, 80, 82, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 20, 53, 56, 57, 89, 65, E8, 83, 65, FC, 00, 6A, 01, FF, 15, 90, 90, 40, 00, 59, 83, 0D, 60, CC, 40, 00, FF, 83, 0D, 64, CC, 40, 00, FF, FF, 15, 94, 90, 40, 00, 8B, 0D, 40, AC, 40, 00, 89, 08, FF, 15, 98, 90, 40, 00, 8B, 0D, 3C, AC, 40, 00, 89, 08, A1, 9C, 90, 40, 00, 8B, 00, A3, 68, CC, 40, 00, E8, C3, 00, 00, 00, 83, 3D, 20, AA, 40, 00, 00, 75, 0C, 68, B4, 83, 40, 00, FF, 15, A0, 90...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
32 KB (32,768 bytes)

The file webplugin.exe has been seen being distributed by the following URL.

http://nvr.lupus-ddns.de:37811/webplugin.exe

Scan webplugin.exe - Powered by Reason Core Security