fillogapp.exe

FilogApp Module

Korea Network Technology Center

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Fillog Launcher’.
Publisher:
Korea Network Technology Center  (signed and verified)

Product:
FilogApp Module

Version:
1, 0, 0, 1

MD5:
a0d2811fa0df575ae4137b9302191ced

SHA-1:
a2ccf2b516fa06de6a52f2aeaa5c88fb77a32b5f

SHA-256:
f63f84a514a96bcc1a8da19b49ad5837f8b40fd4959be77aa72a2863d46667ff

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:47:14 AM UTC  (today)

File size:
985.9 KB (1,009,576 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright 2012

Original file name:
FilogApp.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\fillog\fillogapp.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/4/2014 9:00:00 AM

Valid to:
3/5/2015 8:59:59 AM

Subject:
CN=Korea Network Technology Center, O=Korea Network Technology Center, L=Bundang-gu, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0ED75803A06E78DF2596B2E3ADEA5D

File PE Metadata
Compilation timestamp:
4/18/2014 5:06:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:7qeaatcpAe0nQbW06A7xVS74XPgQqSpNQhsDlKdywi2vU2Kdywi2vUNoVPCziQ3:24JXA7xrXPhqS0h1J

Entry address:
0x3D33A

Entry point:
E8, 5A, 97, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8D, 42, FF, 5B, C3, 8D, A4, 24, 00, 00, 00, 00, 8D, 64, 24, 00, 33, C0, 8A, 44, 24, 08, 53, 8B, D8, C1, E0, 08, 8B, 54, 24, 08, F7, C2, 03, 00, 00, 00, 74, 15, 8A, 0A, 83, C2, 01, 3A, CB, 74, CF, 84, C9, 74, 51, F7, C2, 03, 00, 00, 00, 75, EB, 0B, D8, 57, 8B, C3, C1, E3, 10, 56, 0B, D8, 8B, 0A, BF, FF, FE, FE, 7E, 8B, C1, 8B, F7, 33, CB, 03, F0, 03, F9, 83, F1, FF, 83, F0, FF, 33, CF, 33, C6, 83, C2, 04, 81, E1, 00, 01...
 
[+]

Entropy:
6.3592

Code size:
310.5 KB (317,952 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Fillog Launcher

Command:
C:\Program Files\fillog\fillogapp.exe \autorun


Scan fillogapp.exe - Powered by Reason Core Security