odin3v1.87.exe

TODO: <제품 이름>

Samsung Electronics Co., Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from docviewer.yandex.com and multiple other hosts.
Publisher:
Samsung Electronics Co., Ltd.

Product:
TODO: <제품 이름>

Description:
Odin3 Communicator

Version:
1.0.8.7

MD5:
df92df9a6f565a41180830ec4f62aae5

SHA-1:
7ef3e72f524b6f7a9476a134fff17d7ad9db6183

SHA-256:
babcff66cd5f664aa94a5396a817c56dbfc8e5d4c247a75c44c6cfb3391c7e1b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:10:32 AM UTC  (today)

File size:
417 KB (427,008 bytes)

Product version:
1.0.8.7

Copyright:
TODO: (c) <회사 이름>. All rights reserved.

Original file name:
Odin3.exe

File type:
Executable application (Win32 EXE)

Language:
Korean

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\sgs-gt-i9000 flash + pit\odin3v1.87\odin3v1.87.exe

File PE Metadata
Compilation timestamp:
10/21/2011 7:59:57 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:/vliSAJRmYw8oNYncVu/wool65kHdY227YNtvQr5EP:J8pncVu/woolC227YvQr

Entry address:
0x2C685

Entry point:
E8, 30, 5C, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 14, 47, 45, 00, 75, 02, F3, C3, E9, B2, 5C, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, C3, 1B, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 31, 0C, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 78, 5D, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 37, 1F, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Code size:
263 KB (269,312 bytes)

The file odin3v1.87.exe has been seen being distributed by the following 5 URLs.

https://docviewer.yandex.com/source?id=3qrn-40w2dq7bgl80lqd9zavipc4515jpra5a6nv4b2su96mhgobtu3btojr7nbnw69u2rqkjue6ft8uz58b9z0gcn4v6kku8l0tibcx&archive-path=//.../Odin3v1.87.exe&ts=157d6941042&token=qsE5Pcg2EtWN7wO1nEIfYQ==&name=Odin3v1.87.rar

https://docviewer.yandex.ua/source?id=3qrn-40w2dq7bgl80lqd9zavipc4515jpra5a6nv4b2su96mhgobtu3btojr7nbnw69u2rqkjue6ft8uz58b9z0gcn4v6kku8l0tibcx&archive-path=//.../Odin3v1.87.exe&ts=15785dd15e4&token=G9hsMnoaqI5OHDOGMjna9A==&name=Odin3v1.87.rar

http://115.238.233.136/file/MDAwMDAwMDFjoc8Wec1W4UYUYZ29sFioqSMUDx7w94G8nPuiClYTKw../.../Odin3v1.87.exe

Scan odin3v1.87.exe - Powered by Reason Core Security