cafcon.exe

CAFCON Co.,Ltd.

The application cafcon.exe by CAFCON Co.,Ltd has been detected as a potentially unwanted program by 6 anti-malware scanners.
Publisher:
CAFCON Co.,Ltd.  (signed and verified)

Version:
4.07

MD5:
d94465692de6431a9a6ea7e64c128a60

SHA-1:
df1f5111ab93e6e0ac3fc12c402dbcf11a36dd51

SHA-256:
8a832c8e2ec6e39e155dd0dbd41095d85ca955e97f63e595b39ad779a043c94b

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 9:24:14 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Cafcon
2015.02.05

Comodo Security
UnclassifiedMalware
20959

Dr.Web
BACKDOOR.Trojan
9.0.1.0308

McAfee
GenericR-ARB!D94465692DE6
5600.6592

Sophos
Mal/VB-GI
4.98

VIPRE Antivirus
Trojan.Win32.Generic
37250

File size:
1.4 MB (1,452,600 bytes)

Product version:
4.07

Original file name:
cafcon.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cafcon\cafcon.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
12/23/2013 4:00:00 PM

Valid to:
12/24/2014 3:59:59 PM

Subject:
CN="CAFCON Co.,Ltd.", OU=IT Team, O="CAFCON Co.,Ltd.", L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
39C5BD8C073E535063B058AD0A5F35CD

File PE Metadata
Compilation timestamp:
6/30/2014 1:43:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:vtoRKABnLNlmoSoVoUoP7TKdZtyq/4aCNCmCjhevUTnHOouM:rABnLNlG2ZtyqRC4mCjheMgM

Entry address:
0x3BE0

Entry point:
68, C4, E9, 42, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, DA, 08, C1, F4, 9E, 1E, 90, 42, 8E, CD, D7, B7, 84, D3, 46, E6, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 63, 61, 66, 63, 6F, 6E, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 29, 8D, 61, F2, 5F, 21, F8, 2F, 44, A9, DF, AF, A0, 89, AA, E8, 6D, 97, 3B, E4, 91, B3, 6A, EF, 43, AB, 22, 51, 1B, 08, 31, 8C, 95, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Entropy:
4.6084

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
1.2 MB (1,261,568 bytes)

Remove cafcon.exe - Powered by Reason Core Security