YesfileDown.exe

YesfileDown

BankPrime.Corp

Publisher:
Bankmedia Corp.  (signed by BankPrime.Corp)

Product:
YesfileDown

Description:
예스파일 다운로드 프로그램

Version:
1.0.0.1

MD5:
c7941067ebd3d64fe3588850d209b972

SHA-1:
acc3ab08956c8bb9c7904893ee9ff5d171b0effe

SHA-256:
5d4b0f35940dd3a7dfb18c293f871ad52fb4aae8fb83e5d2bcbc27d8ef505ff2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/9/2025 7:05:05 PM UTC  (today)

File size:
3.3 MB (3,505,064 bytes)

Product version:
1.0.0.1

Copyright:
Bankmedia Corp.

Original file name:
YesfileDown.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\yesfiledown.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
10/6/2015 9:00:00 AM

Valid to:
1/5/2018 8:59:59 AM

Subject:
CN=BankPrime.Corp, O=BankPrime.Corp, L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
665BECF936AEFDD2FDE006DA1CF1D783

File PE Metadata
Compilation timestamp:
10/26/2016 1:19:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Ik6O6ZYCsz8evOROPUHGQdEQDqafCuHSqnebd05lf6n0PQa/OUdtvmBDMOlRa5Hc:IyCszALiizLSqnud05uaG6tMMOloxc

Entry address:
0x5A968

Entry point:
E8, EA, B4, 00, 00, E9, 78, FE, FF, FF, 6A, 10, 68, 68, A3, 48, 00, E8, AE, 07, 00, 00, 8B, 5D, 08, 85, DB, 75, 0E, FF, 75, 0C, E8, 29, FC, FF, FF, 59, E9, CC, 01, 00, 00, 8B, 75, 0C, 85, F6, 75, 0C, 53, E8, 39, FB, FF, FF, 59, E9, B7, 01, 00, 00, 83, 3D, 28, 6F, 49, 00, 03, 0F, 85, 93, 01, 00, 00, 33, FF, 89, 7D, E4, 83, FE, E0, 0F, 87, 8A, 01, 00, 00, 6A, 04, E8, 18, A2, 00, 00, 59, 89, 7D, FC, 53, E8, 41, A2, 00, 00, 59, 89, 45, E0, 3B, C7, 0F, 84, 9E, 00, 00, 00, 3B, 35, 18, 6F, 49, 00, 77, 49, 56, 53...
 
[+]

Entropy:
4.8369

Code size:
461.5 KB (472,576 bytes)

The file YesfileDown.exe has been seen being distributed by the following URL.

http://webfile.yesfile.com/app/yesfile/setup/.../YesfileDown.exe

Scan YesfileDown.exe - Powered by Reason Core Security