Game.exe

TianLongBaBu

Beijing AmazGame Age Internet Technology Co., Ltd.

The application Game.exe by Beijing AmazGame Age Internet Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Changyou.com limited  (signed by Beijing AmazGame Age Internet Technology Co., Ltd.)

Product:
TianLongBaBu

Description:
8inw

Version:
0, 85, 0, 0

MD5:
f82c3fe929ec6cd26fb185886b3cc478

SHA-1:
bf5ef222384f75694c2deadff8f433bd42ed1ff9

SHA-256:
1d5264692fe86cbd28e019cd24971c2b0b3a2580399ca5f5cb46968e1bf85f28

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 4:03:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.BeijingA
17.3.10.20

File size:
1.1 MB (1,153,144 bytes)

Product version:
0, 85, 0, 0

Copyright:
(C) 2008-2009 Changyou.com Limited.All Rights Reserved

Original file name:
Game.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\asiasoft\8inw\bin\game.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/28/2009 7:00:00 AM

Valid to:
4/28/2012 6:59:59 AM

Subject:
CN="Beijing AmazGame Age Internet Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
131E7EB34A7DB63E08A235718EEF6849

File PE Metadata
Compilation timestamp:
5/16/2011 9:31:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x1000

Entry point:
68, 01, 60, 68, 00, E8, 01, 00, 00, 00, C3, C3, B0, 92, 3D, C4, 63, F8, 36, 2F, 3B, BE, 37, 33, B1, 84, EA, E7, CE, CB, 43, 37, 94, 7F, 64, 14, BF, 74, 3E, 8C, 16, 80, C5, 88, 35, 97, 4A, 23, 3C, 59, CA, 3F, CF, 24, 30, E0, 4E, 4D, 6F, DE, 18, 27, A9, E6, C8, 2A, C4, 48, 84, E4, F7, FC, 9D, BF, 6D, EE, 3A, E3, 82, E9, 45, D0, DF, C5, 73, D3, 90, D7, EF, 53, D9, 2E, 8C, 31, F0, 36, B4, 4D, 24, 13, 0D, DD, 2D, F5, 07, 4E, B7, 09, C4, E7, 8E, 79, DB, EB, F1, 7F, 4D, 49, 61, 7F, 22, AD, 08, C5, A5, E1, 58, 64...
 
[+]

Entropy:
7.9461

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
1.9 MB (2,019,328 bytes)

Remove Game.exe - Powered by Reason Core Security