selfupdate_cf2.exe

SelfUpdate Module

Neowiz Corporation

The executable selfupdate_cf2.exe has been detected as malware by 28 anti-virus scanners.
Publisher:
Neowiz Corporation  (signed and verified)

Product:
SelfUpdate Module

Version:
1, 0, 0, 6

MD5:
996e76fd92f586999148f17765da8dd6

SHA-1:
6a864afe33c34378a7e5b3017aeafc1eb6124f77

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/25/2024 8:33:42 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Slugin
2011.01.10

Avira AntiVirus
W32/Slugin.A
7.11.1.76

avast!
Win32:Patched-HO
2014.9-160106

AVG
Win32/Slugin.A
2017.0.2872

Bitdefender
Win32.SlugIn.A
1.0.20.30

Clam AntiVirus
Trojan.Spy-59563
0.98/17411

Comodo Security
TrojWare.Win32.Patched.P
7351

Dr.Web
Win32.Wplugin.1
9.0.1.06

ESET NOD32
Win32/Slugin
10.5773

Fortinet FortiGate
W32/Wplug.A
1/6/2016

F-Prot
W32/Slugin.B
v6.4.6.2.117

F-Secure
Win32.SlugIn.A
11.2016-06-01_4

G Data
Win32.SlugIn
16.1.21

IKARUS anti.virus
Trojan.Win32.Patched
t3scan.1.1.90.0

K7 AntiVirus
Trojan
13.75.3472

Kaspersky
Trojan.Win32.Patched
14.0.0.857

McAfee
W32/Wplugin
5600.6528

Microsoft Security Essentials
Virus:Win32/Slugin.A
1.163.1557.0

Norman
W32/Slugin.A
11.20160106

nProtect
Win32.SlugIn.A
11.01.10.01

Panda Antivirus
W32/Wplugin.A
16.01.06.12

Quick Heal
W32.Slugin.A
1.16.11.00

Rising Antivirus
Win32.Agent.ey
23.00.65.16104

Sophos
W32/Slugin-A
4.61

Trend Micro House Call
PE_WPLUG.A
7.2.6

Trend Micro
PE_WPLUG.A
10.465.06

VIPRE Antivirus
Virus.Win32.Slugin.a
8017

ViRobot
Win32.Patched.N
2011.1.10.4246

File size:
213.8 KB (218,979 bytes)

Product version:
1, 0, 0, 6

Copyright:
Copyright 2006

Original file name:
SelfUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Subject:
CN=Neowiz Corporation, OU=System Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Neowiz Corporation, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7AD90EEE82D88A7F32A55A301BD7C494

File PE Metadata
Compilation timestamp:
3/18/2010 10:11:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:FtapsmVNMnDN7v5n+sjU4mOTlVnCe5ctsoYCqhYZ4z1sxtbjIUWnoRzI:Aw579+POTz/5dq9Z4zytbL8

Entry address:
0xB89F

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 00, 10, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 00, 10, 89, 45, 00, 8B, 83, B3, 4B, 00, 10, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 00, 10, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 00, 10, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 00, 10, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Entropy:
6.3674

Packer / compiler:
ASPack v1.08.04

Code size:
76 KB (77,824 bytes)

Remove selfupdate_cf2.exe - Powered by Reason Core Security