WarBoard.exe

Cyber Snipa Warboard Application

SYSTORM Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WarBoard’.
Publisher:
SYSTORM Co., Ltd.  (signed and verified)

Product:
Cyber Snipa Warboard Application

Version:
1, 0, 260, 0

MD5:
0bc2355fc6bab1b6b6faea5c6b675240

SHA-1:
e413e34ad34ee54ccf62b7de7b627d89a551183e

SHA-256:
ee54cd7a88c981dd035fe6722b7ee8eb7c1a13e2e04c1cc22ed4dd2404b61812

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:50:43 AM UTC  (today)

File size:
9.3 MB (9,800,816 bytes)

Product version:
1, 0, 260, 0

Copyright:
Copyright (C) Flexiglow Pty Ltd 2006.

Original file name:
WarBoard.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cyber snipa warboard 1.00\warboard.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/4/2007 8:00:00 AM

Valid to:
9/4/2008 7:59:59 AM

Subject:
CN="SYSTORM Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="SYSTORM Co., Ltd.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
39CAFB7DE76101F0A253BC6AEE524D1D

File PE Metadata
Compilation timestamp:
11/24/2007 12:59:28 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:A7iBwdoUiBwdoUiBwdoUiBwdoUiBwdoNwrwrwfhDwU494949494h:A7iBwdoUiBwdoUiBwdoUiBwdoUiBwdol

Entry address:
0x59EC0

Entry point:
48, 83, EC, 28, E8, 77, AD, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 41, 8B, 00, 48, 8B, DA, 4C, 8B, C9, 44, 8B, D8, 4C, 8B, D1, 41, 83, E3, F8, A8, 04, 74, 13, 41, 8B, 40, 08, 4D, 63, 50, 04, F7, D8, 4C, 03, D1, 48, 63, C8, 4C, 23, D1, 49, 63, C3, 4A, 8B, 14, 10, 48, 8B, 43, 10, 8B, 48, 08, 48, 03, 4B, 08, 0F, B6, 41, 03, A8, 0F, 74, 0B, 0F, B6, C0, 83, E0, F0, 48, 98, 4C, 03, C8, 4C, 33, CA, 49, 8B, C9, 48, 83, C4, 20, 5B...
 
[+]

Entropy:
5.9118

Code size:
465.5 KB (476,672 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WarBoard

Command:
"C:\Program Files\cyber snipa warboard 1.00\warboard.exe" -1


Scan WarBoard.exe - Powered by Reason Core Security