Thorn.exe

THORN

Syncopate LLC

The application Thorn.exe by Syncopate has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Remove Thorn.exe - Powered by Reason Core Security
Publisher:
GGS  (signed by Syncopate LLC)

Product:
THORN

Description:
GameNet Thorn

Version:
0,1,37,536061fd03c189b1cc50e58ecc99e80484949d62

MD5:
b1cf825b45737e098e82913681a951c1

SHA-1:
cca50a0935304c27daa77af94231552d26ce68f3

SHA-256:
64e0341aaee72cbe3e5f6a09c3734ba12b35c8ed446ba3ec7c98e6e5b8d145df

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/4/2016 11:25:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Syncopate
15.4.14.13

Remove Thorn.exe - Powered by Reason Core Security
File size:
35.9 KB (36,720 bytes)

Product version:
0,1,37,536061fd03c189b1cc50e58ecc99e80484949d62

Copyright:
Copyright(c) 2010 - 2012

Original file name:
Thorn.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\thorn\thorn.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/14/2013 4:00:00 AM

Valid to:
11/14/2015 3:59:59 AM

Subject:
CN=Syncopate LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Syncopate LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
251831462EB15F30D8171D997EF0184B

File PE Metadata
Compilation timestamp:
6/10/2014 10:08:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
384:PWQlB78rm/yKNT60+DDHtgwEGqo/lNm9CjpaP5dsj/zx9R5N1h5PbkxkAXNayfzY:P8bt2PRaL7PgxFXve4zr2EONM4TzmjGt

Entry address:
0x2F18

Entry point:
E8, 3C, 05, 00, 00, E9, 63, FD, FF, FF, CC, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, 82, 40, 00, 89, 0D, AC, 82, 40, 00, 89, 15, A8, 82, 40, 00, 89, 1D, A4, 82, 40, 00, 89, 35, A0, 82, 40, 00, 89, 3D, 9C, 82, 40, 00, 66, 8C, 15, C8, 82, 40, 00, 66, 8C, 0D, BC, 82, 40, 00, 66, 8C, 1D, 98, 82, 40, 00, 66, 8C, 05, 94, 82, 40, 00, 66, 8C, 25, 90, 82, 40, 00, 66, 8C, 2D, 8C, 82, 40, 00, 9C, 8F, 05, C0, 82, 40, 00, 8B, 45, 00, A3, B4, 82, 40, 00, 8B, 45, 04, A3, B8, 82, 40, 00, 8D, 45, 08, A3, C4, 82...
 
[+]

Code size:
11.5 KB (11,776 bytes)

Remove Thorn.exe - Powered by Reason Core Security