kakaotalk_setup.exe

KakaoTalk Setup

Kakao corp.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from software.naver.com and multiple other hosts.
Publisher:
Kakao corp.  (signed and verified)

Product:
KakaoTalk Setup

Version:
2.1.0.1072

MD5:
89ee32b2eff2cbfd36709edfde56cb71

SHA-1:
ace87fc1c5495a06d2f1de0d23ce9e38eb93a333

SHA-256:
c759bb8b3b3ba52787e2e453c3aff322153a756897adf4a4a9a4e6b6fd965b85

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/17/2024 5:21:48 AM UTC  (today)

File size:
29.8 MB (31,207,544 bytes)

Product version:
2.1.0.1072

Copyright:
Copyright © Kakao Corp. All rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Korean (Korea)

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
11/9/2015 7:00:00 AM

Valid to:
11/9/2017 6:59:59 AM

Subject:
CN=Kakao corp., O=Kakao corp., L=Jeju-si, S=Jeju-do, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7FF53B37ED385DF86B79FFAAE15EE85B

File PE Metadata
Compilation timestamp:
2/25/2012 2:20:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:8XduXGELTAiuVmopCKPHx4R2ZAYfCCNQ+tVkhpP:qd+AiuVmyRUyJRPLkhR

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9974

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file kakaotalk_setup.exe has been seen being distributed by the following 16 URLs.

http://software.naver.com/api/.../httpDown.nhn?softwareId=GWS_000083|all|GWV_007871&key=dae79b844bf6185e734d884cf621cd7decbe034dbb3a02c380f50e0cbb31a083a6465192c2f6238ea82004ff2bb2870373e29b24a1d21d4f5338d2dc7de741e851a84c0f3ee96d27eacd75bae6efebb0283f03dd54ba43ef67238a7b76fdf3deb11d07e3fa67bf368302860d97a2b01b1cf5f903079c2b45267ee9de3840d5be8a9491b4e3678e80c3f3211e03b444016131ec58ffdf0eea11a2ec7f9d5b13dd889f4d79ddf47d20026aa846999ff48b0def38ea3ae9fe580b351afcb1f25eb0f285acd1b4ea82f224a03f95c854f6620abea192dd1d110d119052b7214dc72f00f6e167d06ae32e24656eabe3bde135721276d24d24064537016675b8f35cb4

http://software.naver.com/api/.../httpDown.nhn?softwareId=GWS_000083|all|GWV_007871&key=dae79b844bf6185e734d884cf621cd7decbe034dbb3a02c380f50e0cbb31a083a6465192c2f6238ea82004ff2bb2870373e29b24a1d21d4f5338d2dc7de741e851a84c0f3ee96d27eacd75bae6efebb0283f03dd54ba43ef67238a7b76fdf3deb11d07e3fa67bf368302860d97a2b01ba2892184bbc570d120fee799841b522e9925caf076b42111936fb9f412306710fa530e1f60ecd68a4782e5455f18f8954a5a405b7ec245d707d2bf7e79220fc2df717dbb8682c424411671174c291d3225834bedc41e555afd1b064ea4e38980dbb8a3c8007ab9f0f84d6ef1f7766db3388c3f9ebbc13fcac72a87b9c2d8873786f0b433c1f3cab270a034f794c99c65

http://software.naver.com/api/.../httpDown.nhn?softwareId=GWS_000083|all|GWV_007871&key=b9d0a19938fc354d78688c22c8077f6ec02f98989daeb57b4ef80a07bd5191aeadb001a2e9a1ce70232e88325616d9ab6c1aae397ca96cad281f8253dbbeb68dcb65c2bd8ed49a449d923a80e6211e2d21f68c1175b6dfe12a5770593260989c068ada6b2bacd352c5a7c58998f584df2341bd01ea5975cb16bc82ecbd806bcd3122bb7b09b0f4956c55dfd5fb7240dba467298ed77e4d1b6f10e33778669905b04dc131750a4d50284f5e0e32f35ab11de817c1dc8ac85588f6f04afd14ae7ad706acbe7a0cda372ab2d623c09e2ac6debd617224809a978850c0e7e6de8fdc24a9788e8735a4aa1225d50a92b5dd17a8895d8507f67b50eb5610d3dc536d96

http://software.naver.com/api/.../httpDown.nhn?softwareId=GWS_000083|all|GWV_007871&key=b9d0a19938fc354d78688c22c8077f6ec02f98989daeb57b4ef80a07bd5191aeadb001a2e9a1ce70232e88325616d9ab6c1aae397ca96cad281f8253dbbeb68dcb65c2bd8ed49a449d923a80e6211e2d21f68c1175b6dfe12a5770593260989c068ada6b2bacd352c5a7c58998f584dfa9a5ede9f8e5500508ea1b542068721ca045e3b30400ad51ba9874540ee11402dd0e1cf1f77d7617a5a44a9cc53a27951a2685f8420d7de9d0fc81fea839c263bc9ff722ad9c04dab9ab5af1208e54981b6625bb1daf67e779e928fdbbe6b3d3a76a10a6583cf3fcb8758aa8870345d44f1cb967f508cc842c6bc7159e06f546ad1c505cee9cca29da09e65b00149476

http://lnkr.us/get?sourceId=15&uid=49544x680x&format=go&out=http://app.pc.kakao.com/talk/win32/KakaoTalk_Setup.exe&ref=http://.../talk

http://software.naver.com/api/.../httpDown.nhn?softwareId=GWS_000083|all|GWV_007871&key=dae79b844bf6185e734d884cf621cd7decbe034dbb3a02c380f50e0cbb31a083a6465192c2f6238ea82004ff2bb2870373e29b24a1d21d4f5338d2dc7de741e851a84c0f3ee96d27eacd75bae6efebb0283f03dd54ba43ef67238a7b76fdf3deb11d07e3fa67bf368302860d97a2b01b3dfa0bb1a3a3838b7c962557807d4120366ec7c14c65d07ba02e63234ea943654b82fe17a0e88622f2da04b1235e4b9d6f3bbbd6814389d5e8d63188956ff2f0bf6c0b7632193c9aaeabf2fbeb5b539abbcbfe601b303c5a7ae55cdbab6bb8dbd15a342ca4c9ff575fc0148ff42b860a79f3950483261211e4aa6c6e76c28b852668e19909062080ccf967410871460f

http://software.naver.com/api/.../httpDown.nhn?softwareId=GWS_000083|all|GWV_007871&key=dae79b844bf6185e734d884cf621cd7decbe034dbb3a02c380f50e0cbb31a083a6465192c2f6238ea82004ff2bb2870373e29b24a1d21d4f5338d2dc7de741e851a84c0f3ee96d27eacd75bae6efebb0283f03dd54ba43ef67238a7b76fdf3deb11d07e3fa67bf368302860d97a2b01b3dfa0bb1a3a3838b7c962557807d41201c98b02cab1cab5b46eb2865c899c1591d6b6d706d3c1a623cb12ed37dcf5270d678348552f8e80df8c6bdce983da20adc1288ad76f6a329b0bbe66fc771ee104c370d69840e7fbc34e189699e57ae70118099261ea22d2c3f30b516b280c849aaf268ba6dfece09744c9102b05aefa2e47abbdf5ec999aba46e0fa365ef4a22

Scan kakaotalk_setup.exe - Powered by Reason Core Security