PATRIOT VIPER MOUSE.EXE

PATRIOT VIPER MOUSE

Areson Technology

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PATRIOT VIPER MOUSE’.
Publisher:
PATRIOT  (signed by Areson Technology)

Product:
PATRIOT VIPER MOUSE

Version:
1.0.0.1

MD5:
eac58cc45889159bbf2210fcd4a3a8c5

SHA-1:
e37b08cfb0f106f2d978f3fdc56667110f0bdd1a

SHA-256:
88fb639d3e523da36610acf3be24773a9724765102a0a4c265679282f9001d19

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/2/2024 9:07:15 PM UTC  (today)

File size:
7.2 MB (7,510,984 bytes)

Product version:
1.0.0.1

Original file name:
PATRIOT VIPER MOUSE.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\patriot viper mouse\patriot viper mouse.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
8/10/2015 8:00:00 AM

Valid to:
10/9/2018 7:59:59 AM

Subject:
CN=Areson Technology, O=Areson Technology, L=New Taipei City, S=Taiwan, C=TW

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6B92E97E5CCBE330A04C562CE782AA6F

File PE Metadata
Compilation timestamp:
9/22/2016 1:40:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
196608:JeQwr0ETUt0t4tXfit+IqzyBCBqxitFLOyomFHKnPa:D6qt0tkf4+IqzyQBMyFH

Entry address:
0x8144A

Entry point:
E8, 5D, 0C, 00, 00, E9, 8E, FE, FF, FF, 3B, 0D, 24, 05, 4C, 00, F2, 75, 02, F2, C3, F2, E9, 9F, 06, 00, 00, 55, 8B, EC, FF, 75, 08, E8, 62, A2, FD, FF, 59, 5D, C3, 55, 8B, EC, A1, 24, 05, 4C, 00, 83, E0, 1F, 6A, 20, 59, 2B, C8, 8B, 45, 08, D3, C8, 33, 05, 24, 05, 4C, 00, 5D, C3, 55, 8B, EC, 8B, 45, 08, 56, 8B, 48, 3C, 03, C8, 0F, B7, 41, 14, 8D, 51, 18, 03, D0, 0F, B7, 41, 06, 6B, F0, 28, 03, F2, 3B, D6, 74, 19, 8B, 4D, 0C, 3B, 4A, 0C, 72, 0A, 8B, 42, 08, 03, 42, 0C, 3B, C8, 72, 0C, 83, C2, 28, 3B, D6, 75...
 
[+]

Entropy:
7.7072  (probably packed)

Code size:
636 KB (651,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PATRIOT VIPER MOUSE

Command:
"C:\Program Files\patriot viper mouse\patriot viper mouse.exe" \hide


Scan PATRIOT VIPER MOUSE.EXE - Powered by Reason Core Security