winapcupsd-3.14.12.exe

apcupsd

The program is a setup application that uses the Nullsoft Install System installer. The file has been seen being downloaded from downloads.sourceforge.net.
Publisher:
apcupsd  (signed and verified)

MD5:
6058a52b40a563fc3b552de53186f970

SHA-1:
91b6d1c09b25a0d713aa060d842e619f768a96a1

SHA-256:
2b01b575255a3695a479ed0eced694bcc7c3e7f50337fd5ea29de7b634d5c993

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:22:49 PM UTC  (today)

File size:
5.8 MB (6,124,976 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\winapcupsd-3.14.12.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
8/10/2013 12:22:18 PM

Valid to:
8/10/2014 12:22:18 PM

Subject:
E=akropel1@rochester.rr.com, CN="Open Source Developer, Adam Kropelin", O=apcupsd, C=US

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
65189D2D3092ECFA8F08C43B3B6F5B27

File PE Metadata
Compilation timestamp:
2/3/2014 3:32:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.23

CTPH (ssdeep):
98304:tp4jG4NZ5CgD1uz1gphtriHFMRBj5WF3TMyzOhj1qzahJbdarlad2K9NQIpIa7UM:L4dCgDqO3poMH5Nszahckd2K9WN

Entry address:
0x37F0

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 8B, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 2E, 43, 00, 00, 6A, 00, E8, 9F, 46, 00, 00, A3, 48, 3C, 42, 00, 6A, 08, E8, 6A, 28, 00, 00, A3, F8, 3C, 42, 00, 6A, 00, 68, 60, 01, 00, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, 4C, 92, 40, 00, E8, E4, 45, 00, 00, 83, EC, 0C, 68, 4D, 92, 40, 00, 68, 28, 3D, 42, 00, E8, 8A, 2A, 00, 00, 83, C4, 18, E8, EA, 42, 00, 00, 52, 52, 50, 68, 00, C0, 42, 00, E8, 75, 2A, 00, 00, 57, 6A, 00, E8, 45, 42, 00, 00, A3...
 
[+]

Entropy:
7.9987  (probably packed)

Code size:
28 KB (28,672 bytes)

The file winapcupsd-3.14.12.exe has been seen being distributed by the following URL.

Scan winapcupsd-3.14.12.exe - Powered by Reason Core Security