dbrebirth v3.exe

Tibia Player

CipSoft GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from www69.zippyshare.com and multiple other hosts.
Publisher:
CipSoft GmbH

Product:
Tibia Player

Version:
8.54

MD5:
d10f8992e68b18a811ed5b1196417508

SHA-1:
bc84f12321a92fe47c7ef87075367d0b9a5fd5fa

SHA-256:
81a63aeb20eefb07cff195eaf4ca47bd3e0376780989eddb671e8b5cd211c00b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:34:33 AM UTC  (today)

File size:
22.5 MB (23,548,521 bytes)

Product version:
8.54

Copyright:
Copyright (C) CipSoft GmbH 2002-2009

Trademarks:
Tibia is a registered Trademark of CipSoft GmbH.

Original file name:
Tibia.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dbrebirth v3.exe

File PE Metadata
Compilation timestamp:
12/8/2009 10:45:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:NuD/+12skgxwzZ7GEfA42zOsRXU1TKKD7jaVlkMwTN1mcYtXO+HQmkcjKOGQvOp2:It8aZiE4BzkNvGViMwhkcmHYrOIpyGW

Entry address:
0x3FFB33

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, D4, A1, E6, E8, 41, 2B, 93, C6, 0F, 8D, BB, BB, 64, 2D, 59, 9F, 2D, 9B, 62, CE, 6F, 4E, 2C, 81, C0, DB, 17, 6D, F4, 5D, FD, 1E, 4D, C1, C6, A8, 18, 67, 2B, E3, 63, A0, 3E, 6B, 25, 02, D1, 73, C9, BB, 19, 2C, 6A, AA, 54, F4, C9, BB, 19, 2C, 6A, AA, 54, F4, E9, 1A, 6D, 00, 00, E9, 2E, 6D, 00, 00, E9, 29, 6D, 00, 00, E8, 6E, FB, FF, FF, 6E, 04, 01, 00, 88, 99, 00, 00, 73, 5D, F0, 68, 13, 3B, D1, 86, 54, C2, 74, C6, 36, 56, 91, 7F, 0C, 41, D0, 8D, 9A, 48, 69, 95, E9...
 
[+]

Packer / compiler:
MoleBox v2.0

The file dbrebirth v3.exe has been seen being distributed by the following 13 URLs.

http://www69.zippyshare.com/d/6yDV5Bua/.../DBRebirth v3.exe

Scan dbrebirth v3.exe - Powered by Reason Core Security