ins.exe

Installer 응용 프로그램

Kings Information & Network Co., Ltd.

Publisher:
Kings Information & Network  (signed by Kings Information & Network Co., Ltd.)

Product:
Installer 응용 프로그램

Description:
i-Defense3.1 수동 설치 파일 Setup

Version:
1, 0, 1, 5

MD5:
93cf82f76f4e645dfc67ea0274da6651

SHA-1:
9bed8c1d9a1f0561216071f67fdeca5c5f4ff045

SHA-256:
127659b7e26b5978c4e77d1c739c82272b18b6a16f38b7e2620ed76695b5e0a7

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 6:59:27 PM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.XPACK.cqpaua
0.28.0.58873

Rising Antivirus
PE:Malware.Packed!1.9C4E
23.00.65.14524

File size:
15.1 MB (15,859,600 bytes)

Product version:
1, 0, 1, 5

Copyright:
Copyright (C) 2007 Kings Information & Network

Original file name:
Installer.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ins.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/13/2013 9:00:00 AM

Valid to:
9/13/2014 8:59:59 AM

Subject:
CN="Kings Information & Network Co., Ltd.", OU=Business Support Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Kings Information & Network Co., Ltd.", L=Hanamsi, S=Gyeonggido, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
141647F7F25B6F6C4A132B4C592E800A

File PE Metadata
Compilation timestamp:
3/19/2014 4:06:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:XFpx1gC7k9bAhx1PJYmPSiUorYjfNcBSwR:XFpx1gC7k9mxVeuUV7NIdR

Entry address:
0x1045D8

Entry point:
E8, BA, AD, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 70, 92, 57, 00, 00, 75, 18, E8, 88, A6, 00, 00, 6A, 1E, E8, D2, A4, 00, 00, 68, FF, 00, 00, 00, E8, 33, 02, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 70, 92, 57, 00, FF, 15, 58, 92, 52, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 78, 92, 57, 00, 74, 0D, 53, E8, FD, AD, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 7F, 0A, 00, 00, 89, 30, E8, 78, 0A, 00, 00, 89...
 
[+]

Entropy:
6.9074

Code size:
1.2 MB (1,211,904 bytes)

The file ins.exe has been seen being distributed by the following URL.

Scan ins.exe - Powered by Reason Core Security