runer.exe

Cong ty dau tu va phat trien cong nghe thong tin

Publisher:

MD5:
73c6b0756e44c62247394772878d2163

SHA-1:
c662f61f3ba22a7d66801ac918c830160d93993a

SHA-256:
78d41abadb0a238c3dcc0a88997191f26ad3bb8703c68455c765796560fee689

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/5/2024 12:05:57 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Avira AntiVirus
BDS/Rogue.154624
7.11.189.158

IKARUS anti.virus
Backdoor.Rogue
t3scan.1.8.3.0

McAfee
Artemis!73C6B0756E44
5600.6930

Trend Micro House Call
Suspicious_GEN.F47V1122
7.2.335

File size:
157.3 KB (161,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\vtcgame\dot kich\runer.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/30/2013 7:00:00 AM

Valid to:
8/26/2015 6:59:59 AM

Subject:
CN=Cong ty dau tu va phat trien cong nghe thong tin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cong ty dau tu va phat trien cong nghe thong tin, L=Hanoi, S=Hanoi, C=VN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F318FA88A92CCE830CC187023EC0B36

File PE Metadata
Compilation timestamp:
10/23/2014 1:36:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:DtoKn1TChWwV32Q2P4LxEiCMAkScsFhmQOTL+ZfQwO6jv:Dtoc1TcWwHLxCMZSc2HOf+ZfSs

Entry address:
0x1ED39

Entry point:
B8, 68, C7, 45, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 36, D0, E2, 68, B0, B5, FB, 85, DD, 0F, 59, B5, AC, 3E, 88, 94, 27, 01, 9D, C6, E5, A9, 72, 70, B1, DC, 46, 87, 79, 1C, D7, 19, CB, 5A, 49, 71, C6, FE, F3, D9, A6, BC, 19, A8, 7A, E1, BC, 3F, 95, D9, 90, 85, 39, FC, 2A, 7F, D2, 71, 83, E3, 17, C9, 59, A6, 91, 54, 5D, DC, 07, C2, FD, 0B, AA, 56, AA, AA, EA, E4, 48, E2, 47, 03, 64, DF, 3C, 09, 8F, FD, 26, E2, D2, 19, 9A...
 
[+]

Packer / compiler:
PECompact v2

Code size:
224 KB (229,376 bytes)

Scan runer.exe - Powered by Reason Core Security