noribox_n-2elcz3az450z60i5.exe

노리박스 시작 프로그램

NextepMedia, Inc.

The executable noribox_n-2elcz3az450z60i5.exe, “노리박스 실행을 위해 구동되는 프로그램” has been detected as malware by 6 anti-virus scanners. The file has been seen being downloaded from www.nextepserver.co.kr.
Publisher:
NextepMedia,Inc.  (signed by NextepMedia, Inc.)

Product:
노리박스 시작 프로그램

Description:
노리박스 실행을 위해 구동되는 프로그램

Version:
1, 3, 0, 4

MD5:
880a4af7208433f7a4e359d74284789a

SHA-1:
9083f8af1b4c64b09056d5e0d91097a000da6d69

SHA-256:
3dee1633a26df7e9093c3aa8a5d80021796f85976ff8d134f363b67e2ebc122e

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
1/15/2025 4:08:37 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Rogue.9982263
7.11.214.140

Dr.Web
Trojan.DownLoader5.53486
9.0.1.034

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.6.0

NANO AntiVirus
Trojan.Win32.Rogue.cyupus
0.30.0.296

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38196

File size:
31.6 KB (32,392 bytes)

Product version:
1, 3, 0, 4

Copyright:
(c) NextepMedia,Inc. All rights reserved.

Original file name:
NoriBoxGate.EXE

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\users\{user}\downloads\noribox_n-2elcz3az450z60i5.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/17/2011 7:00:00 AM

Valid to:
8/16/2012 6:59:59 AM

Subject:
CN="NextepMedia, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NextepMedia, Inc.", L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
39D723F36659D922C5892A14965295A6

File PE Metadata
Compilation timestamp:
2/21/2012 1:59:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:gRLiEU0XnpruFawd1rCskrGjBK48weuYJLcJ+eAveMz2g:ALSawjrveLLeAGg

Entry address:
0x1CBE

Entry point:
55, 8B, EC, 6A, FF, 68, A0, 22, 40, 00, 68, 44, 1E, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 30, 21, 40, 00, 59, 83, 0D, 18, 32, 40, 00, FF, 83, 0D, 1C, 32, 40, 00, FF, FF, 15, 34, 21, 40, 00, 8B, 0D, 0C, 32, 40, 00, 89, 08, FF, 15, 38, 21, 40, 00, 8B, 0D, 08, 32, 40, 00, 89, 08, A1, 3C, 21, 40, 00, 8B, 00, A3, 14, 32, 40, 00, E8, 16, 01, 00, 00, 39, 1D, 20, 31, 40, 00, 75, 0C, 68, 40, 1E, 40, 00, FF, 15, 40, 21...
 
[+]

Entropy:
4.5444

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
4 KB (4,096 bytes)

The file noribox_n-2elcz3az450z60i5.exe has been seen being distributed by the following URL.

Remove noribox_n-2elcz3az450z60i5.exe - Powered by Reason Core Security