KebiBigBroker.exe

KebiBigBroker (ActiveX Broker)

Nara Vision co.,Ltd

Publisher:
Naravision  (signed by Nara Vision co.,Ltd)

Product:
KebiBigBroker (ActiveX Broker)

Version:
1.0.0.8

MD5:
0fa10ffdb93a70f28693618f4ac2a985

SHA-1:
0019a17bfe82f47953dd81c7a33c5fa6a17f2251

SHA-256:
816cd034980cedd8eb0548b012de8a63dd4eb2bdf0e77761ad5b5e262c0222c7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/25/2024 8:59:44 AM UTC  (today)

File size:
1.8 MB (1,880,296 bytes)

Product version:
1.0.0.8

Copyright:
(c) Naravision. All rights reserved.

Original file name:
KebiBigBroker.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\kebibigbroker.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
11/25/2008 5:10:02 PM

Valid to:
11/25/2009 5:10:02 PM

Subject:
CN="Nara Vision co.,Ltd", OU=Software Development Department, O="Nara Vision co.,Ltd", L=SEOUL, S=GYEONGGI-DO, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
59E26001E824122B96367DE62DC8BDCB

File PE Metadata
Compilation timestamp:
10/28/2009 5:15:36 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:ptQ2nX50MkzmOQjEMPrSIyB6Os1wrPKdas7Eu0:bQ601zmrIMPrSIytywrKV

Entry address:
0x1182FB

Entry point:
E8, 60, CC, 00, 00, E9, 78, FE, FF, FF, 83, 38, 00, 56, 8B, F2, 74, 16, 57, 8A, 16, 84, D2, 74, 0E, 8B, 39, 88, 17, FF, 01, 46, FF, 08, 83, 38, 00, 75, EC, 5F, 5E, C3, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, F2, 33, D2, 89, 55, FC, 39, 55, 08, 74, 35, 83, 39, 01, 8B, 37, 76, 19, 6A, 0A, 99, 5B, F7, FB, 80, C2, 30, 88, 16, 46, FF, 09, 8B, 11, 85, C0, 7E, 05, 83, FA, 01, 77, E7, 8B, 07, 89, 37, 4E, 8A, 10, 8A, 0E, 88, 16, 4E, 88, 08, 40, 3B, C6, 72, F2, EB, 2E, 3B, 31, 73, 28, 4E, 8D, 56, 01, 85, D2, 74, 17, 6A...
 
[+]

Entropy:
6.5494

Code size:
1.3 MB (1,323,520 bytes)

The file KebiBigBroker.exe has been seen being distributed by the following URL.

Scan KebiBigBroker.exe - Powered by Reason Core Security