Game.exe

TianLongBaBu

Beijing AmazGame Age Internet Technology Co., Ltd.

The application Game.exe by Beijing AmazGame Age Internet Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Changyou.com limited  (signed by Beijing AmazGame Age Internet Technology Co., Ltd.)

Product:
TianLongBaBu

Description:
《新天龙八部》

Version:
0, 85, 0, 0

MD5:
ea32dbf7ecc9f8cca46e26f2376074bc

SHA-1:
a2526e64f566605d404c7d3f1fc4e5458511af03

SHA-256:
7d5f04cb2cf23eab23882f385178c9536f8e6dfafc369ee568abde07395529e5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 4:51:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.BeijingA
17.3.8.6

File size:
2.5 MB (2,671,176 bytes)

Product version:
0, 85, 0, 0

Copyright:
(C) 2008-2009 Changyou.com Limited.All Rights Reserved

Original file name:
Game.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/18/2015 8:00:00 AM

Valid to:
6/17/2018 7:59:59 AM

Subject:
CN="Beijing AmazGame Age Internet Technology Co., Ltd.", O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
32986F1A747EDB31B8BB8BD88A2A0D03

File PE Metadata
Compilation timestamp:
3/4/2017 9:47:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x1000

Entry point:
68, 01, 00, 4E, 01, E8, 01, 00, 00, 00, C3, C3, 7C, 1F, E6, DF, 8B, 99, 87, BA, 95, 09, CD, 74, E9, DC, 8A, A9, 91, D6, 47, C9, AC, 61, 55, CA, 91, 4A, 3A, AE, CD, 7B, 0B, A1, 5E, 65, 97, CC, 49, 2C, CE, 4B, 33, 0E, 3C, 9F, 33, 30, F3, D5, BD, 28, 34, 7F, 84, 93, A2, 3D, 9B, B0, 2D, 61, B5, A5, DD, 0C, D2, EE, 7A, 84, 16, 5A, 18, AE, 5E, 6B, 2A, ED, 8C, BC, 85, DD, 86, 1D, E6, AA, 7D, EA, E2, 3D, 18, 49, A5, 76, 80, 54, B3, D2, E6, 80, 70, 81, B7, 0A, 1D, 0C, CB, B3, 8C, F3, 79, 97, 4F, 26, 9B, 80, 01, 7C...
 
[+]

Entropy:
7.6896

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4.8 MB (5,062,656 bytes)

Remove Game.exe - Powered by Reason Core Security