alienPlay.EXE

System Q Ltd

Publisher:
System Q Ltd  (signed and verified)

Description:
alienPlay

Version:
6, 0, 0, 5

MD5:
df5e583f72cece085348c0455ffabf73

SHA-1:
79b17baa3075f32aa493bfc615b4e66751260d86

SHA-256:
883a520ff91962716bee8ee9626a1556d4fe31ef7f9fcbd3fdc4a6f177630451

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/19/2025 5:35:24 PM UTC  (today)

Scan engine
Detection
Engine version

Norman
Obfuscated_NA
11.20140805

File size:
1.3 MB (1,362,096 bytes)

Product version:
6, 0, 0, 5

Copyright:
CopyRight (C) 2011

Original file name:
alienPlay.EXE

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\alienplay.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/2/2010 10:56:47 AM

Valid to:
3/2/2013 10:56:44 AM

Subject:
E=software@systemq.com, CN=System Q Ltd, OU=Software, O=System Q Ltd, L=Chesterfield, S=Derbyshire, C=GB

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001271FC17FF3

File PE Metadata
Compilation timestamp:
8/2/2011 9:44:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:yIFKqu4sX2eixF1oGKZWmnqqpNnceo9Ggg0GrbkRKB+Hf+jD+MB61Iut73ANQM4E:yIFA+HxTKgMnq9IbkR4oq6E615ZANX

Entry address:
0x211000

Entry point:
9C, 60, E8, 02, 00, 00, 00, 33, C0, 8B, C4, 83, C0, 04, 93, 8B, E3, 8B, 5B, FC, 81, EB, 07, 20, 40, 00, 87, DD, 01, AD, BB, 2F, 40, 00, 01, AD, E5, 30, 40, 00, 01, AD, 5E, 30, 40, 00, 01, AD, 92, 31, 40, 00, 01, AD, 42, 31, 40, 00, 01, AD, F7, 31, 40, 00, 01, AD, 66, 32, 40, 00, 01, AD, 2F, 32, 40, 00, 01, AD, FD, 34, 40, 00, 01, AD, 52, 35, 40, 00, E8, DF, 0B, 00, 00, E8, 74, 0E, 00, 00, 85, C0, 74, 15, FF, B5, B2, 21, 40, 00, E8, E5, 14, 00, 00, 89, 85, 01, 38, 40, 00, 85, C0, 75, 0E, 8D, 85, 3B, 23, 40...
 
[+]

Entropy:
5.5319

Packer / compiler:
PEBundle v2.0b5 - v2.3

Code size:
116 KB (118,784 bytes)

The file alienPlay.EXE has been seen being distributed by the following URL.

Scan alienPlay.EXE - Powered by Reason Core Security