FileguriMain.exe

파일구리

Iconcube. Inc.

The application FileguriMain.exe by Iconcube has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
(주)아이콘큐브  (signed by Iconcube. Inc.)

Product:
파일구리

Version:
7, 5, 8, 0

MD5:
da944bab85d469c9972cbc2f6b752e7d

SHA-1:
0bfb279f14eb2f3785757c83654195e3e141c579

SHA-256:
441e578826c27adca6908bbb38f353829cfcbb3c596d2512f30d42449fc9b126

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/30/2024 4:50:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.1.7

File size:
13.3 MB (13,896,896 bytes)

Product version:
7, 5, 8, 0

Copyright:
Copyright ⓒ 2000-2016 Iconcube Inc.

Original file name:
FileguriMain.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\iconcube\fileguri\filegurimain.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/20/2016 9:00:00 AM

Valid to:
10/21/2018 8:59:59 AM

Subject:
CN=Iconcube. Inc., OU=IT Team, O=Iconcube. Inc., L=Geumcheon-gu, S=SEOUL, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
767B944D6C8A18776C2BBB51B0EF9FC1

File PE Metadata
Compilation timestamp:
10/31/2016 11:43:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:tpvVbfG/Ei+6noFRPlj+i7iBrs+Oh5oaQKys7rES8yeIk:cli7iBrs+Oh5oaQKys7rES8yxk

Entry address:
0x2D65FF

Entry point:
E8, FD, F7, 00, 00, E9, 16, FE, FF, FF, 3B, 0D, C8, 8F, 7B, 00, 75, 02, F3, C3, E9, 7D, F8, 00, 00, 8B, 01, 8B, 50, FC, 8B, C1, 2B, 42, 04, 8B, 52, 08, 85, D2, 74, 04, 2B, CA, 2B, 01, C3, 55, 8B, EC, 51, 8B, 40, 10, 53, 8B, 58, 08, 56, 33, F6, 85, DB, 57, 8B, 78, 0C, 76, 27, 8B, 04, B7, 8B, 4D, 0C, 89, 45, FC, 8B, 00, 3B, C1, 74, 44, 83, C1, 08, 51, 83, C0, 08, 50, E8, 10, C8, FF, FF, 85, C0, 59, 59, 74, 31, 46, 3B, F3, 72, D9, 33, C0, 5F, 5E, 5B, C9, C3, 8B, 04, B7, F6, 40, 14, 04, 75, F0, 8B, 00, 8B, 4D...
 
[+]

Entropy:
6.0041

Code size:
3.1 MB (3,244,032 bytes)

Windows Firewall Allowed Program
Name:
filegurimain.exe


Remove FileguriMain.exe - Powered by Reason Core Security