bhgui.exe

bhws

Shanghai Bo Yi Information Technology Co. Ltd.

Publisher:
CHINA  (signed by Shanghai Bo Yi Information Technology Co. Ltd.)

Product:
bhws

Description:
Chinese Chess

Version:
2.7.0.0

MD5:
a37a10d98556632030f1f16c38f2a0b8

SHA-1:
865eddedfb4919a330a8f685fab6e20456cba802

SHA-256:
e587fd08ae454541830b50d2ead582ce49efdf53c81be732885801d88414f48e

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 6:36:56 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
2014.9-150810

Comodo Security
TrojWare.Win32.Amtar.KNB
22346

ESET NOD32
Win32/Packed.NoobyProtect.E suspicious (variant)
9.11741

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15808

File size:
12.3 MB (12,872,992 bytes)

Product version:
2.7.0.0

Copyright:
COPYRIGHT(C) 2009~2013

Original file name:
Chess.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/15/2012 8:00:00 AM

Valid to:
3/20/2015 7:59:59 AM

Subject:
CN=Shanghai Bo Yi Information Technology Co. Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Shanghai Bo Yi Information Technology Co. Ltd., L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3BDC743ADE918E2EC09F3A9FDD929776

File PE Metadata
Compilation timestamp:
2/3/2013 1:03:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:zkD2Th9ehV9SfXTWLF2ucUdU9NagQLjWv+Iakw8ndk0+6ctPDAvK5OcbYukf/RVu:QDO9et/1cU6acvCjGMO/A/gYo9ng

Entry address:
0x26C1945

Entry point:
E8, 1C, 00, 00, 00, 53, 61, 66, 65, 6E, 67, 69, 6E, 65, 20, 53, 68, 69, 65, 6C, 64, 65, 6E, 20, 76, 32, 2E, 31, 2E, 34, 2E, 30, 00, 9C, 83, EC, 04, 89, 04, 24, 83, C4, 01, E9, E0, FE, FF, FF, 97, E8, 74, 00, 00, 00, 88, 3C, 24, 8D, 0C, 8D, 00, 00, 00, 00, F7, D8, 66, 8B, FC, 86, EC, EB, 44, C1, 80, 43, FA, 8A, C4, 8A, C4, 8D, 3C, 8D, 00, 00, 00, 00, 8D, 80, 11, 6A, DF, 8E, 03, FD, 66, D3, D1, EB, CB, DD, 55, C5, AC, 5F, BF, FE, 7B, EB, 8E, 7D, DC, 29, 48, EB, 02, BD, 8C, 8D, 80, D1, 9A, F1, 41, 66, D3, D7...
 
[+]

Entropy:
7.8738  (probably packed)

Scan bhgui.exe - Powered by Reason Core Security