joamom_update.exe

쇼핑도우미_update

e-runsesang Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘joamom’.
Publisher:
.  (signed by e-runsesang Co.,Ltd)

Product:
쇼핑도우미_update

Version:
0.02.0001

MD5:
af785a1cd2c96e07ed18263cc3e990a1

SHA-1:
89b7f6060fe3d230b17e0119076af319da34e568

SHA-256:
b7f386721211f5bdd470b5cce6ef9ce5f052e6be7f4b79e4985ebae0d12c8279

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/20/2024 8:16:21 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.VbCrypt.250
9.0.1.05190

File size:
64.2 KB (65,768 bytes)

Product version:
0.02.0001

Original file name:
joamom_update.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mallapp\joamom\joamom_update.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/10/2015 12:00:00 AM

Valid to:
3/11/2016 11:59:59 PM

Subject:
CN="e-runsesang Co.,Ltd", O="e-runsesang Co.,Ltd", L=Seoul, S=Geumcheon-gu, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5E5BAF9FBC94C610F09DF81616E91DA3

File PE Metadata
Compilation timestamp:
12/3/2015 10:35:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:/YzQS6Wyrs/Bwfp0ZVRP4IJ6ca+UVje6UUFH6/Z4VKQC7xFbvSDUf:/YzQPpCVaIJ/a+U31waKJxF+DA

Entry address:
0x1608

Entry point:
68, 7C, 1D, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 36, AD, D7, AC, 9D, A7, 6E, 4C, 8A, 10, 9C, 97, 00, 56, 2E, EA, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 70, 76, 65, 72, 2F, 6D, 6D, 61, 6C, 6C, 61, 70, 70, 5F, 75, 70, 64, 61, 74, 65, 00, 6E, 00, 00, 00, 00, FF, CC, 31, 00, 02, B9, B0, 95, 5B, 9A, AF, 8B, 40, 91, 8F, 41, AB, EF, 18, 21, CD, 21, 28, 8E, 6B, 28, 8E, F0, 46, 9E, F5, EA, 97, 22, 02, 4C, 58, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
6.2700

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
joamom

Command:
C:\Program Files\mallapp\joamom\joamom_update.exe


Scan joamom_update.exe - Powered by Reason Core Security