× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 71ca9c650f3f85db871caf4fba68d6f891d62e01e9fe89b39f723d849114fe3d
File name: Diablo3KeySpammer.exe
Detection ratio: 0 / 57
Analysis date: 2015-03-25 00:07:56 UTC ( 2 years, 7 months ago )
Antivirus Result Update
Ad-Aware 20150324
AegisLab 20150325
Yandex 20150322
AhnLab-V3 20150324
Alibaba 20150324
ALYac 20150324
Antiy-AVL 20150324
Avast 20150324
AVG 20150325
Avira (no cloud) 20150324
AVware 20150325
Baidu-International 20150324
BitDefender 20150324
Bkav 20150323
ByteHero 20150325
CAT-QuickHeal 20150324
ClamAV 20150325
CMC 20150324
Comodo 20150325
Cyren 20150325
DrWeb 20150325
Emsisoft 20150325
ESET-NOD32 20150325
F-Prot 20150325
F-Secure 20150324
Fortinet 20150324
GData 20150324
Ikarus 20150324
Jiangmin 20150324
K7AntiVirus 20150324
K7GW 20150324
Kaspersky 20150324
Kingsoft 20150325
Malwarebytes 20150324
McAfee 20150325
McAfee-GW-Edition 20150324
Microsoft 20150324
eScan 20150325
NANO-Antivirus 20150324
Norman 20150324
nProtect 20150324
Panda 20150324
Qihoo-360 20150325
Rising 20150324
Sophos AV 20150324
SUPERAntiSpyware 20150325
Symantec 20150324
Tencent 20150325
TheHacker 20150324
TotalDefense 20150324
TrendMicro 20150324
TrendMicro-HouseCall 20150324
VBA32 20150324
VIPRE 20150325
ViRobot 20150324
Zillya 20150324
Zoner 20150323
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © 2015

Product Diablo3KeySpammer
Original name Diablo3KeySpammer.exe
Internal name Diablo3KeySpammer.exe
File version 1.16.6.0
Description Diablo3KeySpammer
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2015-03-25 00:00:45
Entry Point 0x0002515E
Number of sections 3
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 4
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 7
PE resources
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
11.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.16.6.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
26624

FileOS
Win32

MIMEType
application/octet-stream

LegalCopyright
Copyright 2015

FileVersion
1.16.6.0

TimeStamp
2015:03:25 01:00:45+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
Diablo3KeySpammer.exe

ProductVersion
1.16.6.0

FileDescription
Diablo3KeySpammer

OSVersion
4.0

OriginalFilename
Diablo3KeySpammer.exe

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
143872

ProductName
Diablo3KeySpammer

ProductVersionNumber
1.16.6.0

EntryPoint
0x2515e

ObjectFileType
Executable application

AssemblyVersion
1.16.6.0

File identification
MD5 788a677b7a8e626abc9686538efc83c4
SHA1 269a31b8038e794760457ef865b060fa4a7eeccf
SHA256 71ca9c650f3f85db871caf4fba68d6f891d62e01e9fe89b39f723d849114fe3d
ssdeep
3072:zyOEcG013Bmyo3qnSMXy8T4cZ7DtxG7qiwG013B:xEP01xmyo3qSMXyxcZ7Do01x

authentihash 7d3eb3d4ca6854bed65ee195c37e66ffa0cd16fe19e21bee6878755a80694f19
imphash f34d5f2d4577ed6d9ceec516c1f5a744
File size 167.0 KB ( 171008 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (56.7%)
Win64 Executable (generic) (21.4%)
Windows Screen Saver (10.1%)
Win32 Dynamic Link Library (generic) (5.0%)
Win32 Executable (generic) (3.4%)
Tags
peexe assembly

VirusTotal metadata
First submission 2015-03-25 00:07:56 UTC ( 2 years, 7 months ago )
Last submission 2015-03-25 00:07:56 UTC ( 2 years, 7 months ago )
File names Diablo3KeySpammer.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!