naruto advanced 0.5c.exe

Tibia Player

CipSoft GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from download1849.mediafire.com and multiple other hosts.
Publisher:
CipSoft GmbH

Product:
Tibia Player

Version:
8.60

MD5:
4ce65c76c4e0bdd6b8a62ef2f9114abb

SHA-1:
238ea8737106de130f81bb72621105716ada937d

SHA-256:
fa31803ad4d68af8890e5624d10179b518808ad728d0096f6614ab9f13e45a59

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 12:46:07 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6979

Dr.Web
Trojan.Inject1.63523
9.0.1.012

File size:
18.7 MB (19,633,479 bytes)

Product version:
8.60

Copyright:
Copyright (C) CipSoft GmbH 2002-2010

Trademarks:
Tibia is a registered Trademark of CipSoft GmbH.

Original file name:
Tibia.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\naruto advanced 0.5c.exe

File PE Metadata
Compilation timestamp:
6/29/2010 6:08:59 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:aw/Y5H/8AREpw+7lg2M+FItes+i18kVlUOMIlk3SWqiOR7niPqJ0Tq4Pxj:auA/8ARV52M4I/fbVWMEq3R7iSSTquj

Entry address:
0x421008

Entry point:
EB, 16, 8B, 15, 00, 10, 82, 00, FF, 32, 8F, 05, 00, 10, 82, 00, EB, 06, 8F, 05, 00, 10, 82, 00, B8, 04, F0, 81, 00, 83, 38, 00, 74, 20, 50, FF, 70, 04, FF, 30, 50, 83, 04, 24, 08, E8, E6, 09, 00, 00, 83, C4, 0C, 58, 8B, 10, C1, E2, 02, 01, D0, 83, C0, 08, EB, DB, E9, 89, 12, 00, 00, 56, 69, 72, 74, 75, 61, 6C, 50, 72, 6F, 74, 65, 63, 74, 00, 00, 00, 00, 00, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 6B, 65, 72, 6E, 65, 6C, 33, 32, 00, 00, 00, 00, 4C, 6F, 63, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 00...
 
[+]

Code size:
860 KB (880,640 bytes)

The file naruto advanced 0.5c.exe has been seen being distributed by the following 2 URLs.

Scan naruto advanced 0.5c.exe - Powered by Reason Core Security