aworld.exe

Activeworlds Browser 4.1

Activeworlds Inc.

This is a setup program which is used to install the application. The file has been seen being downloaded from alicemail10a.rossoalice.alice.it.
Publisher:
Activeworlds Inc.

Product:
Activeworlds Browser 4.1

Version:
4.1.0.982

MD5:
c7449b1efac8c242f1bbc1ca514fc984

SHA-1:
43f97c722eb51f282eb8b379a5b925d105ddbb8b

SHA-256:
4611e203e65cdee1cbc595376cdae766c8472a118c0131d753cc7b6e7c8b07d5

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
1/10/2025 5:47:33 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PC-Guard
7.1.1

Bkav FE
HW32.Packed
1.3.0.4959

File size:
2.3 MB (2,367,488 bytes)

Product version:
4.1.0.982

Copyright:
Copyright © 1995-2008 Activeworlds Inc.

Trademarks:
Active Worlds

Original file name:
aworld

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\miuchiz\aworld.exe

File PE Metadata
Compilation timestamp:
3/11/2008 10:18:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:CvCe1SuBSCBAsYEWmDHbSyy4SPD4DcdhOl53m9GZOa3eVHZ:A1ltBAsDWmS4UXOn3m9Q3aHZ

Entry address:
0x2D1000

Entry point:
FC, 55, 50, E8, 00, 00, 00, 00, 5D, 60, E8, 03, 00, 00, 00, 83, EB, 0E, EB, 01, 0C, 58, EB, 01, 35, 40, EB, 01, 36, FF, E0, 0B, 61, B8, C8, 3B, 41, 00, EB, 01, E3, 60, E8, 03, 00, 00, 00, D2, EB, 0B, 58, EB, 01, 48, 40, EB, 01, 35, FF, E0, E7, 61, 2B, E8, 9C, EB, 01, D5, 9D, EB, 01, 0B, 58, 60, E8, 03, 00, 00, 00, 83, EB, 0E, EB, 01, 0C, 58, EB, 01, 35, 40, EB, 01, 36, FF, E0, 0B, 61, 89, 85, ED, AB, 42, 00, 9C, EB, 01, D5, 9D, EB, 01, 0B, 58, EB, 01, E3, 60, E8, 03, 00, 00, 00, D2, EB, 0B, 58, EB, 01, 48...
 
[+]

Entropy:
7.8904

Packer / compiler:
PC Guard for Win32 v5.00

Code size:
1.6 MB (1,720,320 bytes)

The file aworld.exe has been seen being distributed by the following URL.

Scan aworld.exe - Powered by Reason Core Security