ali213pk_setup3.8.4.7.exe

游侠对战平台 安装程序

杭州凤侠网络科技有限公司

The executable ali213pk_setup3.8.4.7.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
游侠对战平台  (signed by 杭州凤侠网络科技有限公司)

Product:
游侠对战平台 安装程序

Version:
3.8.4.7

MD5:
7f21c5ffba01b18318970bf5dc0398e2

SHA-1:
aac5cdfae250265b78ef4f9eae791272d32c8958

SHA-256:
7d2b18356b3afbb73401bbb132526737426ce7e1f92a2428cd7a329b2b27b8ff

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/14/2024 5:30:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
17.2.24.6

File size:
6 MB (6,286,832 bytes)

Product version:
3.8.4.7

Copyright:
Copyright (C) 游侠网 2014

Original file name:
alipk_setup.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
WoSign CA Limited

Valid from:
9/2/2015 8:59:42 AM

Valid to:
11/2/2017 8:59:42 AM

Subject:
CN=杭州凤侠网络科技有限公司, O=杭州凤侠网络科技有限公司, L=杭州市, S=浙江省, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
662DBF52214E040C9E485417885DBBDF

File PE Metadata
Compilation timestamp:
7/27/2015 10:34:32 PM

OS version:
4.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x3E8400

Entry point:
60, BE, 00, A0, 63, 00, 8D, BE, 00, 70, DC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9930

Packer / compiler:
UPX 2.90LZMA

Code size:
1.7 MB (1,765,376 bytes)

Remove ali213pk_setup3.8.4.7.exe - Powered by Reason Core Security