airmechcanary.exe

Carbon Games Inc.

Publisher:
Carbon Games Inc.  (signed and verified)

MD5:
28f938cb07de99824aa3b805bb523121

SHA-1:
c5e7f589627a125102c783a8a8321136b1dd907f

SHA-256:
2c5ec2e9e4e4d28fc10f7a92c4792cd9436f51a531edc11d991a0b9c6eadf386

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 6:21:53 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
probably unknown NewHeur_PE
9.12193

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

McAfee
Artemis!28F938CB07DE
5600.6649

File size:
323 KB (330,768 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\airmechcanary.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
3/16/2015 5:37:38 AM

Valid to:
3/18/2016 8:37:33 PM

Subject:
CN=Carbon Games Inc., O=Carbon Games Inc., L=Bellevue, S=Washington, C=US

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
01D1FB9CD39318D5

File PE Metadata
Compilation timestamp:
8/24/2015 9:15:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:BAfHHQNLQCibMboz+08+1NzVzXckmvjwlrE+nMW4dzDihM+7LDeDXkYLfxg:BQgJiosvJwkgj8Dnx4dzDij7uAYLfS

Entry address:
0x5221

Entry point:
E8, 98, 5E, 00, 00, E9, 7B, FE, FF, FF, 3B, 0D, 5C, 55, 42, 00, 75, 02, F3, C3, E9, 28, 62, 00, 00, 55, 8B, EC, 8B, 55, 0C, A1, B0, 53, 42, 00, 8B, 4D, 08, 23, 4D, 0C, F7, D2, 23, D0, 0B, D1, 89, 15, B0, 53, 42, 00, 5D, C3, E8, D7, 63, 00, 00, 85, C0, 74, 08, 6A, 16, E8, F5, 63, 00, 00, 59, F6, 05, B0, 53, 42, 00, 02, 74, 21, 6A, 17, E8, 62, 54, 01, 00, 85, C0, 74, 05, 6A, 07, 59, CD, 29, 6A, 01, 68, 15, 00, 00, 40, 6A, 03, E8, 0B, 00, 00, 00, 83, C4, 0C, 6A, 03, E8, 5A, 03, 00, 00, CC, 55, 8B, EC, 81, EC...
 
[+]

Entropy:
5.6324

Code size:
105.5 KB (108,032 bytes)

The file airmechcanary.exe has been seen being distributed by the following URL.

Scan airmechcanary.exe - Powered by Reason Core Security