DsConsole.exe

DiskShot @Net Core Console

Korbos

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Ds@NetCoreConsole’.
Publisher:
Korbos  (signed and verified)

Product:
DiskShot™ @Net Core Console

Version:
3.9.999.0

MD5:
118367b09dc1cf9bea41250ae660a30c

SHA-1:
73c96a03d6ab2d663b13bd659d0e672a4c772bb7

SHA-256:
45e1d2f9759458a0c2c8e940156eb004d02c7bc5be21a5a996213c2ba80b12a3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 5:25:00 PM UTC  (today)

File size:
1.3 MB (1,359,136 bytes)

Product version:
3.9.999.0

Copyright:
ⓒ 1999-2016 Korbos. All rights reserved.

Original file name:
DsConsole.exe

File type:
Executable application (Win64 EXE)

Language:
Korean (Korea)

Common path:
C:\Program Files\korbos\ds@netcore\dsconsole.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/29/2015 5:00:00 PM

Valid to:
8/27/2018 4:59:59 PM

Subject:
CN=Korbos, OU=IT Team, O=Korbos, L=Geumcheon-gu, S=SEOUL, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
05659BF09722D94A5AD408E6C34DB5A1

File PE Metadata
Compilation timestamp:
8/7/2015 12:11:43 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:dfj7856UZMl528TEaAoqmin65RoXPmwkb4CdAFX+F5ZhC:l85FM7267i6/oXu3bdA99

Entry address:
0x8BA80

Entry point:
48, 83, EC, 28, E8, 37, 7B, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 3B, 0D, 49, B5, 06, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, B1, 7B, 00, 00, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8D, 05, 4F, 9D, 03, 00, 8B, DA, 48, 8B, F9, 48, 89, 01, E8, E2, 7C, 00, 00, F6, C3, 01, 74, 08, 48, 8B, CF, E8, 45, 25, FB, FF, 48, 8B, C7, 48, 8B...
 
[+]

Entropy:
6.2079

Code size:
724 KB (741,376 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Ds@NetCoreConsole

Command:
C:\Program Files\korbos\ds@netcore\dsconsole.exe


Scan DsConsole.exe - Powered by Reason Core Security