setup-itemmania.exe

LiveIconSetup

TCOMMS Co,Ltd

This is a self-extracting archive and installer. The file has been seen being downloaded from api.itemmania.liveicon.kr and multiple other hosts.
Publisher:
(C) TComms  (signed by TCOMMS Co,Ltd)

Product:
LiveIconSetup

Version:
2.05

MD5:
f0747572a90477f86faad8b5a88f5b4e

SHA-1:
0c5f66fae325eaa219795c092705ef44da5be811

SHA-256:
820fd33dc241d5a9c98508a6a55cd945361e1a0ecf4c01d84a1a49945dc7e639

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 12:28:57 AM UTC  (today)

File size:
833.9 KB (853,960 bytes)

Product version:
2.05

Copyright:
Copyright TCOMMS Corp. All Rights Reserved.

Original file name:
LiveIconSetup.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\setup-itemmania.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/20/2015 9:00:00 AM

Valid to:
4/19/2017 8:59:59 AM

Subject:
CN="TCOMMS Co,Ltd", OU=Dev. Team, O="TCOMMS Co,Ltd", L=Geumcheon-gu, S=SEOUL, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
751BCB92FE300D140F413132F00719C5

File PE Metadata
Compilation timestamp:
10/28/2016 8:47:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:8VMpZ5FGgvLzB12wMY8vMBp1Uf6nHrpN0+h1rx6TAcocH0pGCqt1y:8VEZ5jvLT2wl6MBUf6nsqx6TAt0Q

Entry address:
0x1018C

Entry point:
55, 8B, EC, 6A, FF, 68, 40, A4, 42, 00, 68, F6, 02, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, E4, 95, 42, 00, 59, 83, 0D, 50, 51, 43, 00, FF, 83, 0D, 54, 51, 43, 00, FF, FF, 15, E8, 95, 42, 00, 8B, 0D, 20, 48, 43, 00, 89, 08, FF, 15, EC, 95, 42, 00, 8B, 0D, 1C, 48, 43, 00, 89, 08, A1, F0, 95, 42, 00, 8B, 00, A3, 4C, 51, 43, 00, E8, 28, 01, 00, 00, 39, 1D, 88, 2C, 43, 00, 75, 0C, 68, 20, 03, 41, 00, FF, 15, F4, 95...
 
[+]

Entropy:
7.2933

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
160 KB (163,840 bytes)

The file setup-itemmania.exe has been seen being distributed by the following 2 URLs.

http://api.itemmania.liveicon.kr/.../setup-itemmania.exe

http://api.itemmania.liveicon.kr/GetSetupFile.api?PID=itemmania

Scan setup-itemmania.exe - Powered by Reason Core Security