PstallSetup.exe

PstallSetup Module

NEOWIZ GAMES CORP.

Publisher:
NEOWIZ GAMES CORP.  (signed and verified)

Product:
PstallSetup Module

Version:
1.0.0.2

MD5:
adc80ac09f3c8e23b5b3821c5e8f175f

SHA-1:
77b02378e8f653fc8a398feda5649f2590a3645d

SHA-256:
c76fe460cc9c8e711e3f3988f714d1420640385f8ace027b3be96e8736523dd1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 3:37:53 AM UTC  (today)

File size:
185.1 KB (189,536 bytes)

Product version:
1.0.0.2

Copyright:
Copyright 2014

Original file name:
PstallSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pstallsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/27/2015 9:00:00 AM

Valid to:
11/26/2016 8:59:59 AM

Subject:
CN=NEOWIZ GAMES CORP., O=NEOWIZ GAMES CORP., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D7B998086DC11B91B95CD83EE44B344

File PE Metadata
Compilation timestamp:
4/26/2016 12:21:17 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:yK/HRV8NoqKWgGyg91YpmoSqsFa9Fh+P+4EThEaV8TyyXyyyyyyyzze3uFA0Z:BsxWwY4o0onvKaV80SpM

Entry address:
0x7B34

Entry point:
E8, 88, 4A, 00, 00, E9, 7F, FE, FF, FF, E9, 9C, 34, 00, 00, FF, 35, 94, 88, 42, 00, FF, 15, 9C, C0, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, C6, 51, 00, 00, 59, 59, E9, DE, 51, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 1E, 52, 00, 00, 59, 85, C0, 74, 11, FF, 75, 08, E8, 95, 34, 00, 00, 59, 85, C0, 74, E6, 8B, E5, 5D, C3, 6A, 01, 8D, 45, FC, C7, 45, FC, 30, C3, 41, 00, 50, 8D, 4D, F0, E8, 28, 2E, 00, 00, 68, 94, 33, 42, 00, 8D, 45, F0, C7, 45, F0, 28, C3, 41, 00, 50, E8, 01, 0C, 00...
 
[+]

Entropy:
6.4395

Code size:
104.5 KB (107,008 bytes)

The file PstallSetup.exe has been seen being distributed by the following 2 URLs.

https://mail.naver.com/file/download/.../?attachType=normal&mailSN=32897&attachIndex=2&virus=1&domain=mail.naver.com&u=kbj0279

Scan PstallSetup.exe - Powered by Reason Core Security