KSAA002.exe

KSAA002

Kiwoong Information & Communication

Publisher:
KWIC  (signed by Kiwoong Information & Communication)

Product:
KSAA002

Version:
1.00

MD5:
e1ad2bb84945b08a6e45a6ce9cc40539

SHA-1:
e9a17cdcbc5607e71ec7991a4758538d58802d03

SHA-256:
5098dab535f05d6feb4fddfe38e17a9ffea9e3916f6e6702d8d55d3d5ae15194

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/24/2024 5:21:52 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Backdoor.Win32.DarkKomet
t3scan.1.7.8.0

File size:
174.6 KB (178,800 bytes)

Product version:
1.00

Copyright:
Copyright 기웅정보통신(주)

Original file name:
KSAA002.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\common files\kwic\script\zip\ksaa002.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/13/2013 9:00:00 AM

Valid to:
7/13/2015 8:59:59 AM

Subject:
CN=Kiwoong Information & Communication, O=Kiwoong Information & Communication, L=Geumcheon-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3035B976BDCD77DA5F38CA5D161C3D72

File PE Metadata
Compilation timestamp:
8/12/2014 2:35:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:ttYHUUoR8YReuFG6ZZzppIRiBbfCD3R7eR76QI:ttY0GwG6ZGRi9fCTR7ILI

Entry address:
0x2D60

Entry point:
68, 98, 31, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, F2, BA, E8, 58, C8, 54, 40, 4F, 96, 64, D6, CD, D1, 89, 3A, 11, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 4B, 53, 41, 41, 30, 30, 32, 00, 00, 00, 00, 00, FF, CC, 31, 00, 0C, 44, 08, EC, B9, 4F, 10, 2D, 4D, 85, 65, 51, EC, 23, 85, A2, D8, 69, 4C, D7, 7E, 5D, 55, 3A, 44, B0, AB, F6, 68, 9A, 93, FE, FF, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Entropy:
5.7955

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
156 KB (159,744 bytes)

Scan KSAA002.exe - Powered by Reason Core Security