pmbluestackplay.exe

TrayPopup

MEDIAWEB. INC.

Publisher:
MEDIAWEB,INC.  (signed by MEDIAWEB. INC.)

Product:
TrayPopup

Version:
1.0.0.1

MD5:
89cad404e549de92542c3f336fe7d916

SHA-1:
8a070efebb5a1fb253740e79bf69e2680030d7f1

SHA-256:
74bfee9e3b56edc0c724e6466b6f680bc44a5263f75867d029cfad509c072178

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
8/4/2025 6:31:02 AM UTC  (today)

File size:
247.5 KB (253,400 bytes)

Product version:
1.0.0.1

Copyright:
Copyright(c) 1999-2016 MEDIAWEB,INC. All rights reserved.

Original file name:
pmbluestackplay.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pmbluestackplay.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/16/2016 9:00:00 AM

Valid to:
2/16/2019 8:59:59 AM

Subject:
CN=MEDIAWEB. INC., O=MEDIAWEB. INC., L=Geumcheon-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
07A8FF86472E4FB0D06412898E0030A3

File PE Metadata
Compilation timestamp:
2/7/2017 3:03:46 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x7757

Entry point:
E8, DC, 03, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 20, E5, 40, 00, 89, 0D, 1C, E5, 40, 00, 89, 15, 18, E5, 40, 00, 89, 1D, 14, E5, 40, 00, 89, 35, 10, E5, 40, 00, 89, 3D, 0C, E5, 40, 00, 66, 8C, 15, 38, E5, 40, 00, 66, 8C, 0D, 2C, E5, 40, 00, 66, 8C, 1D, 08, E5, 40, 00, 66, 8C, 05, 04, E5, 40, 00, 66, 8C, 25, 00, E5, 40, 00, 66, 8C, 2D, FC, E4, 40, 00, 9C, 8F, 05, 30, E5, 40, 00, 8B, 45, 00, A3, 24, E5, 40, 00, 8B, 45, 04, A3, 28, E5, 40, 00, 8D, 45, 08, A3, 34, E5, 40...
 
[+]

Entropy:
2.8244

Code size:
30 KB (30,720 bytes)

The file pmbluestackplay.exe has been seen being distributed by the following URL.

http://download.mediaweb.co.kr/download/pica/client_Repair/.../pmbluestackplay.exe

Scan pmbluestackplay.exe - Powered by Reason Core Security