oiukjjlhf.exe

Zemi Interactive Co., Ltd.

The executable oiukjjlhf.exe has been detected as malware by 7 anti-virus scanners.
Publisher:
Zemi Interactive Co., Ltd.  (signed and verified)

MD5:
ad165149f9c9da2a3ae2b1ed20cd2cb8

SHA-1:
acd8288cfcc392704051d7824d8b50d1a50aaabc

SHA-256:
df7fd6ac9054dd0dcbee83f6cd3d1d04623a0191eb17d8c8527e5b2fbc52e0d4

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/23/2024 6:04:27 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Agent.XLX (variant)
10.12296

Fortinet FortiGate
W32/Agent.XLX!tr
9/6/2016

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.1.9.5.0

Microsoft Security Essentials
Trojan:Win64/Knokunocci.A
1.1.12101.0

Sophos
Mal/Generic-S
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
44102

File size:
131 KB (134,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\oiukjjlhf.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/9/2013 8:00:00 AM

Valid to:
8/9/2014 7:59:59 AM

Subject:
CN="Zemi Interactive Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zemi Interactive Co., Ltd.", L=SeoChoGu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4505E9AC8D288D763A1088ED1E2C8A60

File PE Metadata
Compilation timestamp:
9/18/2015 5:06:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:pSLePTyk8dCdqwh7G4UZ+YDeVXze6FY9Bk/MWCuVOv4bwp5G:OdCdqwQ4e76H4vWOv4cpE

Entry address:
0x3769

Entry point:
E8, 6A, 3D, 00, 00, E9, 89, FE, FF, FF, C7, 01, D8, D1, 40, 00, E9, B2, 3E, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, D8, D1, 40, 00, E8, 9F, 3E, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 37, FD, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, AD, 3E, 00, 00, C7, 06, D8, D1, 40, 00, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 56, 3F, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, A6, 3E, 00, 00, 59, 85, C0, 74, E6, C9, C3, F6...
 
[+]

Entropy:
5.6327

Code size:
45 KB (46,080 bytes)

Remove oiukjjlhf.exe - Powered by Reason Core Security