csmboot.exe

VNG Corporation

Publisher:
VNG Corporation  (signed and verified)

MD5:
3c7b8740e95cc1fc5cbb49542f1a83be

SHA-1:
387f2b310b86541dafa6db99a7168ae269d60fb0

SHA-256:
2637fed2537e5d1a17fd3ebcd49044d85265a18c29eb9c8a9d0a50a7d7654850

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/26/2024 10:13:51 PM UTC  (today)

File size:
10.2 MB (10,729,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\csmboot.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2015 7:00:00 AM

Valid to:
9/28/2017 6:59:59 AM

Subject:
CN=VNG Corporation, O=VNG Corporation, L=Ho Chi Minh, S=Vietnam, C=VN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
69E915413BDF99A03D3AB8D92C3A2C52

File PE Metadata
Compilation timestamp:
11/20/2015 8:15:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:hRihOK2/x30TUxZNJIy90WHJsv6tWKFdu9C3Kpt:dzVGAJsv6tWKFdu9C6pt

Entry address:
0x66BAA3

Entry point:
E8, 0B, 0A, 00, 00, E9, 63, FD, FF, FF, CC, CC, CC, 83, 3D, B4, 3B, D9, 00, 00, 74, 2D, 55, 8B, EC, 83, EC, 08, 83, E4, F8, DD, 1C, 24, F2, 0F, 2C, 04, 24, C9, C3, 83, 3D, B4, 3B, D9, 00, 00, 74, 11, 83, EC, 04, D9, 3C, 24, 58, 66, 83, E0, 7F, 66, 83, F8, 7F, 74, D3, 55, 8B, EC, 83, EC, 20, 83, E4, F0, D9, C0, D9, 54, 24, 18, DF, 7C, 24, 10, DF, 6C, 24, 10, 8B, 54, 24, 18, 8B, 44, 24, 10, 85, C0, 74, 3C, DE, E9, 85, D2, 79, 1E, D9, 1C, 24, 8B, 0C, 24, 81, F1, 00, 00, 00, 80, 81, C1, FF, FF, FF, 7F, 83, D0...
 
[+]

Entropy:
6.7624

Code size:
6.6 MB (6,901,760 bytes)

The file csmboot.exe has been seen being distributed by the following URL.

Scan csmboot.exe - Powered by Reason Core Security