MPlayer.exe

M플레이어

CJ E&M Corporation

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MPlayer’.
Publisher:
CJ E&M Inc.  (signed by CJ E&M Corporation)

Product:
M플레이어

Version:
6.60.15.0223

MD5:
832aaac1c48bf1b55de487e3bafdf559

SHA-1:
9d037914d030aa8e2f6cd2bd97ab76526117a68a

SHA-256:
f3f93f5cb6da6e40ce3ee6ee4b0446bd0850f6b07abcfd8ce80d2a29b6c974d4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/3/2025 5:41:17 PM UTC  (today)

File size:
2.8 MB (2,927,232 bytes)

Product version:
6.60.15.0223

Copyright:
COPYRIGHT(c) CJ E&M Inc. ALL RIGHTS RESERVED

Original file name:
MPlayer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mnet\mplayer\mplayer.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/20/2016 9:00:00 AM

Valid to:
7/10/2016 8:59:59 AM

Subject:
CN=CJ E&M Corporation, O=CJ E&M Corporation, L=Mapo-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6EF62872C16FCC2E8F9D55225634FB6F

File PE Metadata
Compilation timestamp:
1/11/2016 2:04:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:KqFUlbKs0FhpRKMbD5QyKoDZXn83TFDSjzvrc9qub2feYUH9:KieKHTKQsoDZXn81n

Entry address:
0x18D752

Entry point:
E8, 5A, 06, 00, 00, E9, 4C, FE, FF, FF, 3B, 0D, 28, 20, 62, 00, 75, 02, F3, C3, E9, D6, 02, 00, 00, 83, 3D, 40, 1C, 68, 00, 00, 74, 03, 33, C0, C3, 56, 6A, 04, 6A, 20, FF, 15, 54, E5, 5A, 00, 59, 59, 8B, F0, 56, FF, 15, 28, E2, 5A, 00, A3, 40, 1C, 68, 00, A3, 3C, 1C, 68, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 14, 68, 48, 00, 60, 00, E8, 1D, 07, 00, 00, FF, 35, 40, 1C, 68, 00, 8B, 35, 24, E2, 5A, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 4C, E5, 5A, 00...
 
[+]

Entropy:
6.2474

Code size:
1.7 MB (1,754,112 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MPlayer

Command:
C:\Program Files\mnet\mplayer\mplayer.exe


Scan MPlayer.exe - Powered by Reason Core Security