setup-itemmania.exe

LiveIconSetup

TCOMMS Co,Ltd

This is a setup and installation application. The file has been seen being downloaded from api.itemmania.liveicon.kr and multiple other hosts.
Publisher:
(C) TComms  (signed by TCOMMS Co,Ltd)

Product:
LiveIconSetup

Version:
2.04a

MD5:
c4612db53598f50c1c20b109aeb62e95

SHA-1:
76567ef732a6df992c9f1412f27a1b7f0e67efb7

SHA-256:
897f575f4f4f5526a7e1941be2770875fed35fed5eb51b4a4c616638cd30c2d1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/27/2025 3:57:51 AM UTC  (today)

File size:
833.9 KB (853,960 bytes)

Product version:
2.04a

Copyright:
Copyright TCOMMS Corp. All Rights Reserved.

Original file name:
LiveIconSetup.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup-itemmania.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/20/2015 9:00:00 AM

Valid to:
4/19/2017 8:59:59 AM

Subject:
CN="TCOMMS Co,Ltd", OU=Dev. Team, O="TCOMMS Co,Ltd", L=Geumcheon-gu, S=SEOUL, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
751BCB92FE300D140F413132F00719C5

File PE Metadata
Compilation timestamp:
2/29/2016 2:23:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:GUQ5A4hGgvLzBd2wMY8vMBp1Uf6nHrpN0+h1rx6TAcocH0pGCqt1I:GUIA43vLr2wl6MBUf6nsqx6TAt0m

Entry address:
0x1018C

Entry point:
55, 8B, EC, 6A, FF, 68, 40, A4, 42, 00, 68, F6, 02, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, E4, 95, 42, 00, 59, 83, 0D, 40, 51, 43, 00, FF, 83, 0D, 44, 51, 43, 00, FF, FF, 15, E8, 95, 42, 00, 8B, 0D, 10, 48, 43, 00, 89, 08, FF, 15, EC, 95, 42, 00, 8B, 0D, 0C, 48, 43, 00, 89, 08, A1, F0, 95, 42, 00, 8B, 00, A3, 3C, 51, 43, 00, E8, 28, 01, 00, 00, 39, 1D, 78, 2C, 43, 00, 75, 0C, 68, 20, 03, 41, 00, FF, 15, F4, 95...
 
[+]

Entropy:
7.2928

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
160 KB (163,840 bytes)

The file setup-itemmania.exe has been seen being distributed by the following 2 URLs.

Scan setup-itemmania.exe - Powered by Reason Core Security