nuo.exe

Tibia Player

CipSoft GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from download751.mediafire.com and multiple other hosts.
Publisher:
CipSoft GmbH

Product:
Tibia Player

Version:
8.54

MD5:
af941766d4a10a5acd7ffbfda7b0dd5c

SHA-1:
58fc1fb99001b890b5ebed64a811b06c2214eb2e

SHA-256:
46c4817ac1868b86add0c062985ad8f9eab37de7ec54ff2163a72c12253b2aba

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/16/2024 2:11:33 PM UTC  (today)

File size:
29.5 MB (30,902,803 bytes)

Product version:
8.54

Copyright:
Copyright (C) CipSoft GmbH 2002-2009

Trademarks:
Tibia is a registered Trademark of CipSoft GmbH.

Original file name:
Tibia.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\nuo.exe

File PE Metadata
Compilation timestamp:
12/8/2009 7:45:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:uokGe9YfsZgoUWawjvZe7iF7jq8xPMLHgWmBaT:urLYkZVscZe707jq8pMLAWmBU

Entry address:
0x3F6B33

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, 78, 36, C1, 64, 82, 75, 6B, 4F, 2C, 1F, 34, 2A, 00, 1D, 52, 88, C6, 95, 7E, 69, 85, 9A, 3D, 1C, AF, 54, BD, C9, 7C, C1, 47, A7, 08, EF, EE, E2, 41, BC, 39, F2, E9, 4E, 5B, 70, 35, CB, 07, B9, 72, D1, DC, FC, DB, AE, 2B, 0F, 72, D1, DC, FC, DB, AE, 2B, 0F, E9, 1A, 6D, 00, 00, E9, 2E, 6D, 00, 00, E9, 29, 6D, 00, 00, E8, 6E, FB, FF, FF, 6E, 04, 01, 00, 7A, 99, 00, 00, 5E, 69, 05, 6C, 7A, 60, D1, 96, 35, 0E, 74, 16, 23, 60, 91, EF, 4E, 33, D0, FD, 46, F4, 69, A5, E1...
 
[+]

Packer / compiler:
MoleBox v2.0

The file nuo.exe has been seen being distributed by the following 4 URLs.

http://download751.mediafire.com/vkpq41dbcu5g/.../NuO.exe

Scan nuo.exe - Powered by Reason Core Security