KSAA002.exe

KSAA002

Kiwoong Information & Communication

Publisher:
KWIC  (signed by Kiwoong Information & Communication)

Product:
KSAA002

Version:
1.00

MD5:
80fe942fc6a013904319f613edc3aeca

SHA-1:
4ff6e361ed74e2c59d5fb320036464bd944e0125

SHA-256:
6d5a98ea497992f1ce9fb7bfcb1662cd1ad315147d0cb47b4c6d368c8990bf4a

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 3:56:42 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Backdoor.Win32.DarkKomet
t3scan.2.2.29

File size:
170.6 KB (174,712 bytes)

Product version:
1.00

Copyright:
Copyright 기웅정보통신(주)

Original file name:
KSAA002.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\common files\kwic\script\zip\ksaa002.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/13/2013 9:00:00 AM

Valid to:
7/13/2015 8:59:59 AM

Subject:
CN=Kiwoong Information & Communication, O=Kiwoong Information & Communication, L=Geumcheon-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3035B976BDCD77DA5F38CA5D161C3D72

File PE Metadata
Compilation timestamp:
2/7/2014 10:11:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:t4kbP44jEGF8qwWWWGwI1HMH2Lbhh5Wmh2qx1JeLoKF9oz3PbOCXBTLpxwlZCPQE:t4444g+8MCMWLbZl8jouMlkUIc9

Entry address:
0x2D40

Entry point:
68, 78, 31, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 8A, 77, 50, 7D, 5A, BB, 9E, 40, A4, DA, 6A, 17, B8, 7E, F5, 2C, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4B, 53, 41, 41, 30, 30, 32, 00, 00, 00, 00, 00, FF, CC, 31, 00, 0C, 14, FC, A1, 57, 4E, 99, B3, 45, 83, EA, 0C, 99, BF, 0E, 6D, 74, F3, 77, 2B, 4E, 88, 51, 51, 45, BB, A7, D4, 09, 0E, 74, AA, E9, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Entropy:
5.8532

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
152 KB (155,648 bytes)

Scan KSAA002.exe - Powered by Reason Core Security