bizmessenger.exe

LG Uplus Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BizMessenger’.
Publisher:
LG Uplus Corporation  (signed and verified)

MD5:
f29214b271bdaf96f6b7731df551cfd7

SHA-1:
55bc042ba8823281402f76750ea535c68fd32bc7

SHA-256:
50e5f1853ee72e676fa50f89ccae3b38f0f620cf18dc3e08743a3e6b94190a2d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/20/2025 7:59:02 PM UTC  (today)

File size:
1.6 MB (1,686,736 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\uplusmessenger(pkg)\bizmessenger.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
9/27/2016 9:00:00 AM

Valid to:
10/28/2017 8:59:59 AM

Subject:
CN=LG Uplus Corporation, O=LG Uplus Corporation, L=Jung-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
36BB433C022B67214DEC8D04E411B9A9

File PE Metadata
Compilation timestamp:
6/10/2016 9:51:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:v+TkyBxIr3XvOyLk0yM+rwuOa3+4QxAArU2o30g7bLKmHjaOyS/uJ:gkyIr3XvrLk0yM+rwuOXDAArUTxfLKmW

Entry address:
0xF4FED

Entry point:
E8, 03, 92, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, A8, 48, 56, 00, 00, 75, 18, E8, 68, 84, 00, 00, 6A, 1E, E8, B2, 82, 00, 00, 68, FF, 00, 00, 00, E8, B5, 0C, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, A8, 48, 56, 00, FF, 15, 54, 92, 51, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, B0, 48, 56, 00, 74, 0D, 53, E8, 46, 92, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 79, 0B, 00, 00, 89, 30, E8, 72, 0B, 00, 00, 89...
 
[+]

Entropy:
6.3503

Code size:
1.1 MB (1,143,296 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BizMessenger

Command:
C:\Program Files\uplusmessenger(pkg)\bizmessenger.exe


Scan bizmessenger.exe - Powered by Reason Core Security