× Бисквитките са забранени! Този сайт изисква бисквитките да бъдат разрешени, за да работи правилно.
SHA256: edbe44c4e10c08e95d3f2946fc0ce793bbbfedbee18207096b17d284b6282408
Име на файла: PlayTFM.exe
Съотношение на разпознаване: 3 / 56
Дата на анализиране: 2016-03-20 13:21:10 UTC (преди 3 години, 2 месеци) Преглед на последния
Антивирусен софтуер Резултат Версия на обновление
ESET-NOD32 a variant of Win32/HackTool.CheatEngine.AF potentially unsafe 20160320
GData Win32.Riskware.Hacktool.D 20160320
Qihoo-360 HEUR/QVM03.0.0000.Malware.Gen 20160320
Ad-Aware 20160320
AegisLab 20160320
Yandex 20160316
AhnLab-V3 20160320
Alibaba 20160320
ALYac 20160319
Antiy-AVL 20160320
Arcabit 20160320
Avast 20160320
AVG 20160320
Avira (no cloud) 20160320
AVware 20160320
Baidu 20160318
Baidu-International 20160320
BitDefender 20160320
Bkav 20160319
ByteHero 20160320
CAT-QuickHeal 20160319
ClamAV 20160319
CMC 20160316
Comodo 20160320
Cyren 20160320
DrWeb 20160320
Emsisoft 20160320
F-Prot 20160320
F-Secure 20160320
Fortinet 20160320
Ikarus 20160320
Jiangmin 20160320
K7AntiVirus 20160320
K7GW 20160320
Kaspersky 20160320
Malwarebytes 20160320
McAfee 20160320
McAfee-GW-Edition 20160320
Microsoft 20160320
eScan 20160320
NANO-Antivirus 20160320
nProtect 20160320
Panda 20160320
Rising 20160320
Sophos AV 20160320
SUPERAntiSpyware 20160320
Symantec 20160320
Tencent 20160320
TheHacker 20160319
TrendMicro 20160320
TrendMicro-HouseCall 20160320
VBA32 20160318
VIPRE 20160320
ViRobot 20160319
Zillya 20160320
Zoner 20160320
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © 2016

Product PlayTFM
Original name PlayTFM.exe
Internal name PlayTFM.exe
File version 1.0.0.0
Description PlayTFM
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-03-20 12:24:51
Entry Point 0x0040F50E
Number of sections 4
.NET details
Module Version ID 50020519-0d44-4159-aac6-bd6b99b1eed3
TypeLib ID ff6f5440-f54d-4d31-bea8-14dbe23d7777
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 4
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
6.0

LinkerVersion
11.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.0.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
70144

EntryPoint
0x40f50e

OriginalFileName
PlayTFM.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright 2016

FileVersion
1.0.0.0

TimeStamp
2016:03:20 13:24:51+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
PlayTFM.exe

ProductVersion
1.0.0.0

FileDescription
PlayTFM

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
4249088

ProductName
PlayTFM

ProductVersionNumber
1.0.0.0

FileTypeExtension
exe

ObjectFileType
Executable application

AssemblyVersion
1.0.0.0

File identification
MD5 6e8e57bfb05f55ce4d7a902f1ef2d2cd
SHA1 36da3beadf6a85bb83f99efeaccd039ac83c9810
SHA256 edbe44c4e10c08e95d3f2946fc0ce793bbbfedbee18207096b17d284b6282408
ssdeep
98304:iF9UNwLrn7qXK/PnTtb48ihXNn+xsyxNUWlamQNEQmVb6F9:o9i8rnea/PnTtEhX6sywF+RVbQ9

authentihash 14cfd5628c78198789b023cd8a11f5d42739307bdc3b033ea714faec0e2dbaee
imphash f34d5f2d4577ed6d9ceec516c1f5a744
File size 4.1 MB ( 4320256 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (45.1%)
Win32 Executable MS Visual C++ (generic) (19.2%)
Win64 Executable (generic) (17.0%)
Windows screen saver (8.0%)
Win32 Dynamic Link Library (generic) (4.0%)
Tags
peexe assembly

VirusTotal metadata
First submission 2016-03-20 13:21:10 UTC (преди 3 години, 2 месеци)
Last submission 2016-03-20 13:21:10 UTC (преди 3 години, 2 месеци)
Имена на файла PlayTFM.exe
Няма коментари. Никой не е коментирал това, бъдете първи!

Оставете своя коментар…

?
Публикуване

Не сте влезли в акаунта си. Само регистрирани потребители могат да коментират. Влезте и оставете своя коментар!

Няма гласове. Никой не е гласувал за това все още, бъдете първи!