PstallSetup.exe

PstallSetup Module

NEOWIZ GAMES CORP.

Publisher:
NEOWIZ GAMES CORP.  (signed and verified)

Product:
PstallSetup Module

Version:
1.0.0.3

MD5:
c2d53167c234d6db83a1309d3440279d

SHA-1:
f464c8e0a282031d1b3a094726fa73baf56943d5

SHA-256:
d6aa3d29cb210da6570bb55708858d140f3e29a508fc89d2266ca8ac5b619304

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/25/2025 6:33:15 AM UTC  (today)

File size:
184.1 KB (188,512 bytes)

Product version:
1.0.0.3

Copyright:
Copyright 2014

Original file name:
PstallSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pstallsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/27/2015 9:00:00 AM

Valid to:
11/26/2016 8:59:59 AM

Subject:
CN=NEOWIZ GAMES CORP., O=NEOWIZ GAMES CORP., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D7B998086DC11B91B95CD83EE44B344

File PE Metadata
Compilation timestamp:
7/5/2016 10:32:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:5a2CRuBg9E9MdyintBMOp2tPC+gYrjv5q+PiT6FTVnTS8TyyXyyyyyyyzI53hxcl:0d90OMA3cwYhu80Shx47X

Entry address:
0x7784

Entry point:
E8, 88, 4A, 00, 00, E9, 7F, FE, FF, FF, E9, 9C, 34, 00, 00, FF, 35, 94, 78, 42, 00, FF, 15, 98, B0, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, C6, 51, 00, 00, 59, 59, E9, DE, 51, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 1E, 52, 00, 00, 59, 85, C0, 74, 11, FF, 75, 08, E8, 95, 34, 00, 00, 59, 85, C0, 74, E6, 8B, E5, 5D, C3, 6A, 01, 8D, 45, FC, C7, 45, FC, 30, B3, 41, 00, 50, 8D, 4D, F0, E8, 28, 2E, 00, 00, 68, B4, 22, 42, 00, 8D, 45, F0, C7, 45, F0, 28, B3, 41, 00, 50, E8, 01, 0C, 00...
 
[+]

Entropy:
6.4366

Code size:
103.5 KB (105,984 bytes)

The file PstallSetup.exe has been seen being distributed by the following 3 URLs.

http://pubcommon.dl.pmang.com/pubcommon/GameManager/PstallSetup/.../PstallSetup.exe

http://dl.pmang.com/pubcommon/GameManager/PstallSetup/.../PstallSetup.exe

http://dl.pmang.com/pubcommon/GameManager/PstallSetup/.../PstallSetup.exe

Scan PstallSetup.exe - Powered by Reason Core Security