terrariainvedit.563.exe

Terraria Inventory Editor

ChbShoot.me

This is a setup program which is used to install the application. The file has been seen being downloaded from download1988.mediafire.com and multiple other hosts.
Publisher:
ChbShoot.me

Product:
Terraria Inventory Editor

Version:
5.6.3.0

MD5:
e53be3ca50de1f78cc2994f4324b63f0

SHA-1:
97db76fdb43858c2a97c0f176ca48a68722ef56f

SHA-256:
ed7572ced5e15c4f86210ae9fb3f26c8720391ef11d797e7ae7121b615bb084d

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/19/2024 1:54:01 PM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V1027
7.2.160

File size:
6.6 MB (6,874,112 bytes)

Product version:
5.6.3.0

Copyright:
Copyright © ChbShoot, Anthony, and Sifl 2013

Original file name:
TerrariaInvEdit.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\terrariainvedit.563.exe

File PE Metadata
Compilation timestamp:
10/25/2013 8:48:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:uO7YYxAaMTX9/ptVAlIpT36OxVrbgnbLabQUTCaxhhTxc3g8SMqPlmIa:u3OMTXtbZpT3JxgwQMC2hhTxhWka

Entry address:
0x6771BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 68, 00, 00, 80, 10, 00, 00, 00, 80, 00, 00, 80, 18, 00, 00, 00, 98, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7677

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6.5 MB (6,771,200 bytes)

The file terrariainvedit.563.exe has been seen being distributed by the following 3 URLs.

http://download1988.mediafire.com/1gb00khvdj1g/.../TerrariaInvEdit.563.exe

Scan terrariainvedit.563.exe - Powered by Reason Core Security