Game.exe

TianLongBaBu

Beijing AmazGame Age Internet Technology Co., Ltd.

The application Game.exe by Beijing AmazGame Age Internet Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Changyou.com limited  (signed by Beijing AmazGame Age Internet Technology Co., Ltd.)

Product:
TianLongBaBu

Description:
Dragon of Heaven

Version:
0, 85, 0, 0

MD5:
570d089e34e980a29aca7b2df4fafa69

SHA-1:
5943bf7cfc49ae2ac5a5745cdad5790e8b95ecaf

SHA-256:
d30bcd1f0957ef506f6d2fb99f125766c754111088681f2bae0908ff77cb6a0e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/2/2024 7:02:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.BeijingA
17.2.13.16

File size:
1.1 MB (1,149,048 bytes)

Product version:
0, 85, 0, 0

Copyright:
(C) 2008-2009 Changyou.com Limited.All Rights Reserved

Original file name:
Game.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\cib net station\dh\bin\game.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/28/2009 8:00:00 AM

Valid to:
4/28/2012 7:59:59 AM

Subject:
CN="Beijing AmazGame Age Internet Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
131E7EB34A7DB63E08A235718EEF6849

File PE Metadata
Compilation timestamp:
9/26/2010 10:58:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x1000

Entry point:
68, 01, 30, 68, 00, E8, 01, 00, 00, 00, C3, C3, FA, F7, F1, C3, 28, E5, F9, A9, 2F, D5, 4D, 92, 66, 59, 86, 32, 94, E7, 71, 7E, 47, 37, A3, 39, A2, 2F, 8E, 7D, 2C, B7, 7D, 89, F6, 8D, 73, C4, 51, 9F, 13, A0, BB, CC, 2B, FC, AE, C9, 68, A1, C9, FD, 2B, 7B, AB, F7, 2B, B5, 83, F4, 01, A0, 3C, 1E, 17, B8, 53, D7, 7A, 7C, FB, 4C, 14, 6F, 4F, 98, 18, 27, B9, FE, CE, DA, EA, 78, CC, 94, C4, 54, 71, 74, 12, 67, 6A, 41, C8, D0, 14, 00, ED, E6, 80, C9, D1, DE, 5F, A7, 28, 00, F4, 6A, C5, 10, CF, 6F, 52, 5C, 4D, 70...
 
[+]

Entropy:
7.9460

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
1.9 MB (2,011,136 bytes)

Remove Game.exe - Powered by Reason Core Security