kisa_nprotect_s213_20140408.exe

yessign

The executable kisa_nprotect_s213_20140408.exe has been detected as malware by 7 anti-virus scanners.
Publisher:
yessign  (signed and verified)

MD5:
cc25263c5957f5f1bd3a41f41915676e

SHA-1:
b6d04788d0c990917f1dea72fe8c31aa8bfe2000

SHA-256:
7cd70a6168e078f420069bcaa8e9dd09b002f6d44c9106c3f6226d5031d00a1d

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/25/2024 7:26:42 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160209-2

Dr.Web
Trojan.Inject1.10883
9.0.1.05190

ESET NOD32
Win32/TrojanDropper.Agent.PYF trojan
7.0.302.0

Kaspersky
Trojan-Dropper.Win32.Daws
15.0.0.562

McAfee
Trojan.PWSZbot-FIB!CC25263C5957
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6155.0

VIPRE Antivirus
Threat.4789471
47028

File size:
2.6 MB (2,681,721 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\윈포스3\kisa_nprotect_s213_20140408.exe

Digital Signature
Signed by:

Authority:
yessign

Valid from:
10/1/2013 3:00:00 PM

Valid to:
10/5/2014 2:57:59 PM

Subject:
CN=한국인터넷진흥원, OU=02201110050001, OU=code-sign, O=yessign, C=kr

Issuer:
CN=yessignCA General Class 2, OU=AccreditedCA, O=yessign, C=kr

Serial number:
073402DA7F28976885DA

File PE Metadata
Compilation timestamp:
3/5/2012 5:37:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:nMrt6SW+EQjbswBbTChxKCnFnQXBbrtgb/iQvu0UHO7:MrtBW+ZswB6hxvWbrtUTrUHO7

Entry address:
0x167F

Entry point:
55, 8B, EC, 6A, FF, 68, F8, 20, 40, 00, 68, 30, 18, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, D4, 20, 40, 00, 59, 83, 0D, 90, 30, 40, 00, FF, 83, 0D, 94, 30, 40, 00, FF, FF, 15, D0, 20, 40, 00, 8B, 0D, 8C, 30, 40, 00, 89, 08, FF, 15, CC, 20, 40, 00, 8B, 0D, 88, 30, 40, 00, 89, 08, A1, C8, 20, 40, 00, 8B, 00, A3, 98, 30, 40, 00, E8, 35, 01, 00, 00, 39, 1D, 70, 30, 40, 00, 75, 0C, 68, 22, 18, 40, 00, FF, 15...
 
[+]

Entropy:
7.9735

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2.5 KB (2,560 bytes)

Remove kisa_nprotect_s213_20140408.exe - Powered by Reason Core Security