popcapgame1.exe

Zuma Deluxe

Product:
Zuma Deluxe

Description:
Zuma

Version:
1, 0, 0, 1

MD5:
3c58057e95c571280bb2965bc0dcb168

SHA-1:
f0875894adb13ba6e5a8e73ada09ee9f3a3fbf4e

SHA-256:
02465b1e4234656cfbcb91cd743612c17a699f773632fb743691afb52cb187e4

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/23/2024 2:48:00 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/Trojan2.NZSI
v6.4.7.1.166

herdProtect (fuzzy)
2015.8.2.22

K7 AntiVirus
Trojan
13.174.10455

nProtect
Trojan/W32.Agent.1290240.F
2009.1.8.0

Quick Heal
Trojan.Agent.ATV
5.15.10.00

File size:
1.2 MB (1,290,240 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2003

Original file name:
Zuma.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\popcap games\zuma deluxe\popcapgame1.exe

File PE Metadata
Compilation timestamp:
12/5/2003 3:05:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
24576:FdTPnzaQLMXvIILHv5qK+9lyzv/vaLrQc0GgEdXbwF46U8WfMRZmo:zzjCwePoR9O3UdXbwF46U8iMPmo

Entry address:
0xE2948

Entry point:
6A, 60, 68, A8, 8B, 51, 00, E8, 64, 79, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, D0, F7, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, F0, E0, 4F, 00, 8B, 4E, 10, 89, 0D, D8, 05, 58, 00, 8B, 46, 04, A3, E4, 05, 58, 00, 8B, 56, 08, 89, 15, E8, 05, 58, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, DC, 05, 58, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, DC, 05, 58, 00, C1, E0, 08, 03, C2, A3, E0, 05, 58, 00, 33, F6, 56, 8B, 3D, B8, E0, 4F, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.6542

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
1012 KB (1,036,288 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to etg-01-008.etg.ras.cantv.net  (200.44.26.8:80)

TCP (HTTP):
Connects to 128.253.36.199.in-addr.arpa  (199.36.253.128:80)

Scan popcapgame1.exe - Powered by Reason Core Security