PstallSetup.exe

PstallSetup Module

NEOWIZ GAMES CORP.

Publisher:
NEOWIZ GAMES CORP.  (signed and verified)

Product:
PstallSetup Module

Version:
1, 0, 0, 1

MD5:
b2a0ef8388656452c39adc19270b3c80

SHA-1:
d1959fdb13440c271963d2dffb4ad6b7b024e46b

SHA-256:
c25f4688a6965bf0fcdc54009f3538bfa6652d71df3b201aad7c0fd314955d7e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:08:31 AM UTC  (today)

File size:
184.6 KB (189,024 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright 2014

Original file name:
PstallSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\{random}\pstallsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/27/2015 9:00:00 AM

Valid to:
11/26/2016 8:59:59 AM

Subject:
CN=NEOWIZ GAMES CORP., O=NEOWIZ GAMES CORP., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D7B998086DC11B91B95CD83EE44B344

File PE Metadata
Compilation timestamp:
2/5/2016 1:14:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:kjrCSCluE2FCUCGQB7xpSqPCEBxxyqi+5YMAMFTagf8TyyXyyyyyyyzUC3Z77z1:kkKWxsHEDJiuVf80JZXp

Entry address:
0x78C4

Entry point:
E8, 88, 4A, 00, 00, E9, 7F, FE, FF, FF, E9, 9C, 34, 00, 00, FF, 35, 94, 78, 42, 00, FF, 15, 98, B0, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, C6, 51, 00, 00, 59, 59, E9, DE, 51, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 1E, 52, 00, 00, 59, 85, C0, 74, 11, FF, 75, 08, E8, 95, 34, 00, 00, 59, 85, C0, 74, E6, 8B, E5, 5D, C3, 6A, 01, 8D, 45, FC, C7, 45, FC, 30, B3, 41, 00, 50, 8D, 4D, F0, E8, 28, 2E, 00, 00, 68, 04, 22, 42, 00, 8D, 45, F0, C7, 45, F0, 28, B3, 41, 00, 50, E8, 01, 0C, 00...
 
[+]

Entropy:
6.4300

Code size:
104 KB (106,496 bytes)

The file PstallSetup.exe has been seen being distributed by the following URL.

Scan PstallSetup.exe - Powered by Reason Core Security