tibiatunnel.exe

Chimariko

ICOFX SOFTWARE SRL

This is a setup program which is used to install the application. The file has been seen being downloaded from docs.google.com.
Publisher:
Stellar Information System Ltd  (signed by ICOFX SOFTWARE SRL)

Product:
Chimariko

Version:
1.00

MD5:
c6bd7cfb0d2ee0964d285b4daf5dcb0a

SHA-1:
a1609ad57577a519a7657fe0f92a7be6f94e5132

SHA-256:
aa3a0d1df58984e47e38b84a4e9ef647d9e4de826ab59260ffe992f8bd5220c3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 1:25:32 AM UTC  (today)

File size:
12.8 MB (13,420,728 bytes)

Product version:
1.00

Original file name:
Bain Bain Bain Bain Bain Bain Bain Bain.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\tibiatunnel.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/3/2013 10:00:00 PM

Valid to:
2/4/2016 9:59:59 PM

Subject:
CN=ICOFX SOFTWARE SRL, O=ICOFX SOFTWARE SRL, STREET=str. Teilor nr. 10 sc. 2 ap. 24, L=Floresti, S=Cluj, PostalCode=407280, C=RO

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DE9F0854CD6936A239D0FF5B81756164

File PE Metadata
Compilation timestamp:
4/8/2016 3:46:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:YppNjXc06SG3C5rBH633Smq/zI+HNwQwnbgpOPvaKcZeafC+pwvWlUA8:ApNzcUOC1gq/k+2pnxPiKc9fC+pcac

Entry address:
0x1088

Entry point:
68, E8, 14, 0C, 01, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, D2, 55, E3, 1C, B7, 3A, 31, 45, B1, E2, CD, 32, FA, EB, 14, A5, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 20, 56, 42, 5F, 45, 78, 42, 61, 72, 79, 61, 00, 3D, 20, 00, 00, 00, 00, FF, CC, 31, 00, 01, B2, 16, 5D, 01, 7D, 86, B5, 47, 88, 90, B9, 92, BB, 1E, 41, F7, 29, E2, 3D, F1, 23, 8A, A7, 4D, 8E, AA, C6, AB, 84, 5B, 7C, 65, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
12.8 MB (13,381,632 bytes)

The file tibiatunnel.exe has been seen being distributed by the following URL.

https://docs.google.com/uc?authuser=0&id=0B81hXygtNf8lbHhPSjBsREpfMk0&export=download

Scan tibiatunnel.exe - Powered by Reason Core Security