× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 44b4e647fb4c5ab40ce142423375a2d356332e893796f961fdbc6dd3ef01b300
File name: Farmville 2 Hack Cash Generator.exe
Detection ratio: 1 / 46
Analysis date: 2013-03-05 15:10:18 UTC ( 2 years, 2 months ago ) View latest
Antivirus Result Update
PCTools HeurEngine.ZeroDayThreat 20130305
AVG 20130305
Agnitum 20130305
AhnLab-V3 20130305
AntiVir 20130305
Antiy-AVL 20130305
Avast 20130305
BitDefender 20130305
ByteHero 20130304
CAT-QuickHeal 20130305
ClamAV 20130305
Commtouch 20130305
Comodo 20130305
DrWeb 20130305
ESET-NOD32 20130305
Emsisoft 20130305
F-Prot 20130305
F-Secure 20130305
Fortinet 20130305
GData 20130305
Ikarus 20130305
Jiangmin 20130304
K7AntiVirus 20130304
Kaspersky 20130305
Kingsoft 20130304
Malwarebytes 20130305
McAfee 20130305
McAfee-GW-Edition 20130305
MicroWorld-eScan 20130305
Microsoft 20130305
NANO-Antivirus 20130305
Norman 20130305
Panda 20130305
Rising 20130305
SUPERAntiSpyware 20130305
Sophos 20130305
Symantec 20130305
TheHacker 20130305
TotalDefense 20130305
TrendMicro 20130305
TrendMicro-HouseCall 20130305
VBA32 20130305
VIPRE 20130305
ViRobot 20130305
eSafe 20130211
nProtect 20130305
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Developer metadata
Copyright
Copyright © 2013

Product WindowsApplication2
Original name Farmville 2 Hack Cash Generator.exe
Internal name Farmville 2 Hack Cash Generator.exe
File version 1.0.0.0
Description WindowsApplication2
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-03-05 15:05:19
Link date 4:05 PM 3/5/2013
Entry Point 0x0001DA2E
Number of sections 4
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 3
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
11.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.0.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
6656

FileOS
Win32

MIMEType
application/octet-stream

LegalCopyright
Copyright 2013

FileVersion
1.0.0.0

TimeStamp
2013:03:05 16:05:19+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
Farmville 2 Hack Cash Generator.exe

FileAccessDate
2014:06:12 08:56:15+01:00

ProductVersion
1.0.0.0

FileDescription
WindowsApplication2

OSVersion
4.0

FileCreateDate
2014:06:12 08:56:15+01:00

OriginalFilename
Farmville 2 Hack Cash Generator.exe

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
113664

ProductName
WindowsApplication2

ProductVersionNumber
1.0.0.0

EntryPoint
0x1da2e

ObjectFileType
Executable application

AssemblyVersion
1.0.0.0

File identification
MD5 e1a833ae7f2f705c9196aa14be0569f1
SHA1 a6c59a617653c91264fd9d68376c8bd8765deac4
SHA256 44b4e647fb4c5ab40ce142423375a2d356332e893796f961fdbc6dd3ef01b300
ssdeep
3072:PqZ2cDS+op/5CuGOR7t8QzGfWKpv+sZSABEPnsVW9f:PqooZop/YXMEfWKpvxZSw

imphash f34d5f2d4577ed6d9ceec516c1f5a744
File size 118.5 KB ( 121344 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (55.8%)
Win64 Executable (generic) (21.0%)
Windows Screen Saver (9.9%)
Win32 Dynamic Link Library (generic) (5.0%)
Win32 Executable (generic) (3.4%)
Tags
peexe assembly

VirusTotal metadata
First submission 2013-03-05 15:10:18 UTC ( 2 years, 2 months ago )
Last submission 2014-06-12 07:44:37 UTC ( 11 months, 2 weeks ago )
File names Farmville 2 Hack Cash Generator.exe
e1a833ae7f2f705c9196aa14be0569f1
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!