filejoup.exe

JLS Communication

Publisher:
FileJo  (signed by JLS Communication)

Product:
FileJo

Version:
1.0.2.0

MD5:
0755d7de0c1710e578e9695f65a59c03

SHA-1:
ab40647b6e49317a1fa06e068b427626c479a42b

SHA-256:
78814b8f00b3687a87db6059a7c54e9c7ebb040b9338eb38cb3e40226394058a

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 12:38:18 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan.Win32.Patched
t3scan.1.9.5.0

Trend Micro House Call
Suspicious_GEN.F47V0429
7.2.356

File size:
1.3 MB (1,376,352 bytes)

Product version:
1.0.2.0

Copyright:
FileJo

Original file name:
FileJo.exe

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\users\{user}\appdata\local\temp\filejoup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/2/2014 6:00:00 PM

Valid to:
6/1/2016 6:59:59 PM

Subject:
CN=JLS Communication, O=JLS Communication, L=Bupyeong-gu, S=INCHEON, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
22913A4DB23D9036779E1102D0C7A52E

File PE Metadata
Compilation timestamp:
12/18/2015 7:18:08 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Hwoke/RWvw4HgmnecIkpNRTflv5C2OLuvxrL:HdgwmecIkJjlvfOK

Entry address:
0x455C9

Entry point:
E8, FD, A5, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 56, 8B, 75, 08, 33, DB, 57, 39, 5D, 14, 75, 10, 3B, F3, 75, 10, 39, 5D, 0C, 75, 12, 33, C0, 5F, 5E, 5B, 5D, C3, 3B, F3, 74, 07, 8B, 7D, 0C, 3B, FB, 77, 1B, E8, EF, 00, 00, 00, 6A, 16, 5E, 89, 30, 53, 53, 53, 53, 53, E8, C8, E3, FF, FF, 83, C4, 14, 8B, C6, EB, D5, 39, 5D, 14, 75, 04, 88, 1E, EB, CA, 8B, 55, 10, 3B, D3, 75, 04, 88, 1E, EB, D1, 83, 7D, 14, FF, 8B, C6, 75, 0F, 8A, 0A, 88, 08, 40, 42, 3A, CB, 74, 1E, 4F, 75, F3, EB, 19, 8A, 0A, 88...
 
[+]

Entropy:
4.6208

Code size:
349 KB (357,376 bytes)

Scan filejoup.exe - Powered by Reason Core Security