battleping1.3.3.4.exe

BattlePing

This is a setup and installation application. The file has been seen being downloaded from battleping.com and multiple other hosts.
Publisher:
BattlePing

Product:
BattlePing

Description:
BattlePing Setup Program

Version:
1.3.3.4

MD5:
34b00482421a58dbce642f50fb29ca73

SHA-1:
90985b1e2e46a48b574a4d774f70d8ba325bd958

SHA-256:
25c13c97456392ac957148f16dc59f96052b5c8b3720a0e46d1b41a792c56742

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
10/23/2018 3:35:36 PM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V0201
7.2.89

File size:
5.1 MB (5,310,506 bytes)

Product version:
1.3.3.4

Copyright:
Copyright © BattlePing

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\battleping1.3.3.4.exe

File PE Metadata
Compilation timestamp:
6/20/1992 10:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:LALx68x5KtBUZs9kr6puIlVAV1tV1PGzgEEtn7SUG1hAV1tV1fcNfOk3c:scyk/B9kkDeV1tV1PfEEwUkAV1tV1f0s

Entry address:
0x8749C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 5C, 72, 48, 00, E8, 08, F4, F7, FF, A1, 14, 9B, 48, 00, 8B, 00, E8, C0, 48, FE, FF, A1, 14, 9B, 48, 00, 8B, 00, BA, FC, 74, 48, 00, E8, A7, 44, FE, FF, 8B, 0D, 34, 9C, 48, 00, A1, 14, 9B, 48, 00, 8B, 00, 8B, 15, B8, 40, 47, 00, E8, AF, 48, FE, FF, A1, 14, 9B, 48, 00, 8B, 00, E8, 23, 49, FE, FF, E8, BE, D1, F7, FF, 00, 00, FF, FF, FF, FF, 05, 00, 00, 00, 53, 65, 74, 75, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9425

Developed / compiled with:
Microsoft Visual C++

Code size:
537.5 KB (550,400 bytes)

The file battleping1.3.3.4.exe has been seen being distributed by the following 2 URLs.

Scan battleping1.3.3.4.exe - Powered by Reason Core Security