CreticaActivation.exe

CreticaActivation

Vicentas

Publisher:
Vicentas  (signed and verified)

Product:
CreticaActivation

Version:
4.00.0058

MD5:
7a3cddd20401d4cb9e3c48eb0b191d99

SHA-1:
346c1f7da93d78f2dfd39126254c6db403b3d9ca

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/24/2024 9:43:21 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.VbCrypt.250
9.0.1.0364

File size:
267.7 KB (274,112 bytes)

Product version:
4.00.0058

Copyright:
Vicentas

Original file name:
CreticaActivation.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\data\offline\7eb3167c\7193d1cb\creticaactivation.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/19/2011 6:00:00 PM

Valid to:
12/19/2013 5:59:59 PM

Subject:
CN=Vicentas, O=Vicentas, POBox=152, STREET=Postbox 152, L=Voss, S=Hordaland, PostalCode=5701, C=NO

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
21CA3102AB468AED5217FA7174A6EF1D

File PE Metadata
Compilation timestamp:
11/26/2012 12:24:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:RdqbOOWfeQ4YkrXDyadz27+kM1zWBHbSbPKBV:RgrW2nBnG+LBoebQV

Entry address:
0x8D008

Entry point:
EB, 16, 8B, 15, 00, D0, 48, 00, FF, 32, 8F, 05, 00, D0, 48, 00, EB, 06, 8F, 05, 00, D0, 48, 00, B8, 04, B0, 48, 00, 83, 38, 00, 74, 20, 50, FF, 70, 04, FF, 30, 50, 83, 04, 24, 08, E8, E6, 09, 00, 00, 83, C4, 0C, 58, 8B, 10, C1, E2, 02, 01, D0, 83, C0, 08, EB, DB, E9, 89, 12, 00, 00, 56, 69, 72, 74, 75, 61, 6C, 50, 72, 6F, 74, 65, 63, 74, 00, 00, 00, 00, 00, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 6B, 65, 72, 6E, 65, 6C, 33, 32, 00, 00, 00, 00, 4C, 6F, 63, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 00...
 
[+]

Entropy:
7.7139  (probably packed)

Code size:
224 KB (229,376 bytes)

Scan CreticaActivation.exe - Powered by Reason Core Security