SprgFiles.exe

SprgFiles Application

New Unity Inc

The application SprgFiles.exe, “SprgFiles Downloader Application” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program SprgFiles by https://www.www.springfile.biz. While running, it connects to the Internet address ns1.ibspark.com on port 80 using the HTTP protocol.
Publisher:
New Unity Inc

Product:
SprgFiles Application

Description:
SprgFiles Downloader Application

Version:
4, 0, 0, 1

MD5:
3e46ab416bffc6ff0e2ed160f8c571ed

SHA-1:
f5acad8fc88dbfdcec42886f8d8436d5cdb77b85

SHA-256:
9f1d0b5a793746fc63f4566a2e195d8b362ce61441f6cb8c361e54b3d8385746

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
9/21/2024 12:08:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ExpressFiles.SPRG.Meta (M)
16.2.28.23

File size:
1 MB (1,067,008 bytes)

Product version:
4,0,0,0

Copyright:
Copyright (C) 2016

Original file name:
SprgFiles.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\sprgfiles\sprgfiles.exe

File PE Metadata
Compilation timestamp:
2/11/2016 6:48:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
24576:Mcb4RHYFF0TfZd+D89FrIJJpCNoh+71gjGxaokeo96:McbSYFmTfZd88oG1W4aokeo96

Entry address:
0x21F38

Entry point:
E8, 0E, 07, 00, 00, E9, 80, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 53, 57, 33, FF, 8B, 44, 24, 10, 0B, C0, 7D, 14, 47, 8B, 54, 24, 0C, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 10, 89, 54, 24, 0C, 8B, 44, 24, 18, 0B, C0, 7D, 13, 8B, 54, 24, 14, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 18, 89, 54, 24, 14, 0B, C0, 75, 1B, 8B, 4C, 24, 14, 8B, 44, 24, 10, 33, D2, F7, F1, 8B, 44, 24, 0C, F7, F1, 8B, C2, 33, D2, 4F, 79, 4E, EB, 53, 8B, D8, 8B, 4C, 24, 14, 8B, 54, 24, 10, 8B, 44, 24, 0C...
 
[+]

Entropy:
7.1708

Code size:
280.5 KB (287,232 bytes)

3 Windows Firewall Allowed Programs
Name:
sprgfiles

Name:
F:\Program Files\SprgFiles\SprgFiles.exe

Name:
C:\Program Files\SprgFiles\SprgFiles.exe


The file SprgFiles.exe has been discovered within the following programs.

SprgFiles  by https://www.www.springfile.biz
www.www.springfile.biz
About 1% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ns1.ibspark.com  (54.72.130.67:80)

TCP (HTTP):
Connects to mostprank.guaranteedfact.com  (198.105.208.106:80)

Remove SprgFiles.exe - Powered by Reason Core Security