autoupgrade.exe

IO Entertainment Co., Ltd.

Publisher:
IO Entertainment Co., Ltd.  (signed and verified)

Description:
Lost Saga

Version:
3177

MD5:
39f891773a0e0df686e49301a8c490ee

SHA-1:
64d64c68a0b22ab406cb46ed32c313269feb278d

SHA-256:
39505779868c1c8aa3ea7bd70303218fb981eaa958aa48586bb7d87959a785c1

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/27/2024 1:10:32 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.151125

File size:
1 MB (1,073,576 bytes)

Product version:
0,0,0,1

Copyright:
IO Entertainment Co., Ltd.

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\Program Files\ogplanet\lostsaga\autoupgrade.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/31/2009 8:00:00 PM

Valid to:
6/1/2011 7:59:59 PM

Subject:
CN="IO Entertainment Co., Ltd.", O="IO Entertainment Co., Ltd.", L=Guro-guv, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
6ACEA912E6B8AB245A11E55F5D5AF718

File PE Metadata
Compilation timestamp:
12/17/2010 1:23:59 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
24576:bt+DUWNNTLHjZiBvJ5IqevgWr6PXo7KNtuN:bt1kbiVfCgA+c

Entry address:
0x45FD3

Entry point:
52, BA, 64, 00, 00, 00, 85, D2, 74, 1D, B9, 00, 10, 00, 00, 85, C9, 74, 07, 01, C8, 01, D8, 49, EB, F5, 52, 54, 54, FF, 15, 40, 10, 70, 00, 5A, 4A, EB, DF, 5A, E9, 00, 80, 43, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 09, 00, 01, 00, 00, 00, 58, 00, 00, 80, 02, 00, 00, 00, E8, 00, 00, 80, 03, 00, 00, 00, C0, 01, 00, 80, 05, 00, 00, 00, D8, 01, 00, 80, 06, 00, 00, 00, 08, 02, 00, 80, 0C, 00, 00, 00, 80, 02, 00, 80, 0E, 00, 00, 00, 08, 03, 00, 80, 10, 00, 00, 00, 20, 03, 00, 80, F0, 00, 00...
 
[+]

Entropy:
7.8914  (probably packed)

Code size:
420 KB (430,080 bytes)

Scan autoupgrade.exe - Powered by Reason Core Security