× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: a8d77b2ca2023d3c47988858b390fd9b39ca237ac4b288ac83c8f4f3363c363b
File name: RBG_Setup.exe
Detection ratio: 0 / 62
Analysis date: 2017-06-22 20:25:21 UTC ( 1 month ago )
Antivirus Result Update
Ad-Aware 20170622
AegisLab 20170622
AhnLab-V3 20170622
Alibaba 20170622
ALYac 20170622
Antiy-AVL 20170622
Arcabit 20170622
Avast 20170622
AVG 20170622
Avira (no cloud) 20170622
AVware 20170622
Baidu 20170622
BitDefender 20170622
Bkav 20170622
CAT-QuickHeal 20170622
ClamAV 20170622
CMC 20170619
Comodo 20170622
CrowdStrike Falcon (ML) 20170420
Cyren 20170622
DrWeb 20170622
Emsisoft 20170622
Endgame 20170615
ESET-NOD32 20170622
F-Prot 20170622
F-Secure 20170622
Fortinet 20170622
GData 20170622
Ikarus 20170622
Sophos ML 20170607
Jiangmin 20170622
K7AntiVirus 20170622
K7GW 20170622
Kaspersky 20170622
Kingsoft 20170622
Malwarebytes 20170622
McAfee 20170622
McAfee-GW-Edition 20170622
Microsoft 20170622
eScan 20170622
NANO-Antivirus 20170622
nProtect 20170622
Palo Alto Networks (Known Signatures) 20170622
Panda 20170622
Qihoo-360 20170622
Rising 20170622
SentinelOne (Static ML) 20170516
Sophos AV 20170622
SUPERAntiSpyware 20170622
Symantec 20170622
Symantec Mobile Insight 20170621
Tencent 20170622
TheHacker 20170621
TotalDefense 20170622
TrendMicro 20170622
TrendMicro-HouseCall 20170622
Trustlook 20170622
VBA32 20170622
VIPRE 20170622
ViRobot 20170622
Webroot 20170622
WhiteArmor 20170616
Yandex 20170622
Zillya 20170622
ZoneAlarm by Check Point 20170622
Zoner 20170622
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright

Product Random BackGround
File version 1.4.4
Description Random BackGround Setup
Comments This installation was built with Inno Setup.
Signature verification Signed file, verified signature
Signing date 6:58 AM 2/27/2013
Signers
[+] Open Source Developer, RealityRipple Software
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Certum Level III CA
Valid from 8:26 AM 11/15/2012
Valid to 8:26 AM 11/15/2013
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint A3543A1D933A2E8F8B402163D872E5B8F7E5C58C
Serial number 17 04 12 B2 8A CA D8 A1 F4 DE 75 72 68 1D 14 31
[+] Certum Level III CA
Status Valid
Issuer Certum CA
Valid from 1:53 PM 3/3/2009
Valid to 1:53 PM 3/3/2024
Valid usage All
Algorithm sha1RSA
Thumbprint 827E72353D6910A9DEC7F3D1061676E80356FD53
Serial number 04 7A 53
[+] Certum
Status Valid
Issuer Certum CA
Valid from 11:46 AM 6/11/2002
Valid to 11:46 AM 6/11/2027
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, OCSP Signing
Algorithm sha1RSA
Thumbprint 6252DC40F71143A22FDE9EF7348E064251B18118
Serial number 01 00 20
Counter signers
[+] Certum Time-Stamping Authority
Status Valid
Issuer Certum CA
Valid from 1:58 PM 3/3/2009
Valid to 1:58 PM 3/3/2024
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 0D2CF962FB4D042F2F1401DE66EACBA80DA76112
Serial number 04 7A 55
[+] Certum
Status Valid
Issuer Certum CA
Valid from 11:46 AM 6/11/2002
Valid to 11:46 AM 6/11/2027
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, OCSP Signing
Algorithm sha1RSA
Thumbrint 6252DC40F71143A22FDE9EF7348E064251B18118
Serial number 01 00 20
Packers identified
F-PROT INNO
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 1992-06-19 22:22:17
Entry Point 0x00009C40
Number of sections 8
PE sections
Overlays
MD5 f507fc1980a0def16b4a00af6e144a35
File type data
Offset 125952
Size 1289024
Entropy 8.00
PE imports
LookupPrivilegeValueA
RegCloseKey
OpenProcessToken
RegQueryValueExA
AdjustTokenPrivileges
RegOpenKeyExA
InitCommonControls
GetSystemTime
GetLastError
GetEnvironmentVariableA
GetStdHandle
EnterCriticalSection
GetUserDefaultLangID
GetSystemInfo
GetFileAttributesA
GetExitCodeProcess
ExitProcess
CreateDirectoryA
VirtualProtect
GetVersionExA
RemoveDirectoryA
RtlUnwind
LoadLibraryA
DeleteCriticalSection
GetCurrentProcess
SizeofResource
GetLocaleInfoA
LocalAlloc
LockResource
IsDBCSLeadByte
DeleteFileA
GetWindowsDirectoryA
GetSystemDefaultLCID
SetErrorMode
MultiByteToWideChar
GetCommandLineA
GetProcAddress
FormatMessageA
SetFilePointer
RaiseException
WideCharToMultiByte
GetModuleHandleA
ReadFile
InterlockedExchange
WriteFile
CloseHandle
GetACP
GetFullPathNameA
LocalFree
CreateProcessA
GetModuleFileNameA
InitializeCriticalSection
LoadResource
VirtualQuery
VirtualFree
TlsGetValue
Sleep
GetFileType
SetEndOfFile
TlsSetValue
CreateFileA
FindResourceA
VirtualAlloc
GetFileSize
SetLastError
LeaveCriticalSection
SysStringLen
SysAllocStringLen
VariantCopyInd
VariantClear
VariantChangeTypeEx
CharPrevA
CreateWindowExA
LoadStringA
DispatchMessageA
CallWindowProcA
MessageBoxA
PeekMessageA
SetWindowLongA
MsgWaitForMultipleObjects
TranslateMessage
ExitWindowsEx
DestroyWindow
Number of PE resources by type
RT_ICON 10
RT_STRING 6
RT_MANIFEST 1
RT_RCDATA 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 13
NEUTRAL 7
PE resources
ExifTool file metadata
UninitializedDataSize
0

Comments
This installation was built with Inno Setup.

LinkerVersion
2.25

ImageVersion
6.0

FileSubtype
0

FileVersionNumber
1.4.4.0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
87040

EntryPoint
0x9c40

MIMEType
application/octet-stream

FileVersion
1.4.4

TimeStamp
1992:06:19 23:22:17+01:00

FileType
Win32 EXE

PEType
PE32

SubsystemVersion
4.0

ProductVersion
1.4.4

FileDescription
Random BackGround Setup

OSVersion
1.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
RealityRipple Software

CodeSize
37888

ProductName
Random BackGround

ProductVersionNumber
1.4.4.0

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 1b6ed6a0071cb71799e26a6063b23c76
SHA1 cb55d814ed90dbdf96efaccb51ffe4069f587118
SHA256 a8d77b2ca2023d3c47988858b390fd9b39ca237ac4b288ac83c8f4f3363c363b
ssdeep
24576:CnaKOfPy6A/s7kn2pntYS+GQn3KXVE8nR8Y0zf3wf9ihMHBjH5jd3X0AZq9EDqjM:CaKOfPZr24qS+GQ3KlEhf349iWjVd3hR

authentihash 8dc18a16e96e9da89de049b77506327f47f77c8e7764cf525166d51f8f4703ff
imphash 884310b1928934402ea6fec1dbd3cf5e
File size 1.3 MB ( 1414976 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Inno Setup installer (81.5%)
Win32 Executable Delphi generic (10.5%)
Win32 Executable (generic) (3.3%)
Win16/32 Executable Delphi generic (1.5%)
Generic Win/DOS Executable (1.4%)
Tags
peexe signed overlay

VirusTotal metadata
First submission 2013-03-14 03:27:40 UTC ( 4 years, 4 months ago )
Last submission 2017-06-22 20:25:21 UTC ( 1 month ago )
File names download.php
361698
A8D77B2CA2023D3C47988858B390FD9B39CA237AC4B288AC83C8F4F3363C363B
RBG_Setup.exe
RBG_Setup.exe
141494017167073-RBG_Setup.exe
1b6ed6a0071cb71799e26a6063b23c76.cb55d814ed90dbdf96efaccb51ffe4069f587118
Advanced heuristic and reputation engines
ClamAV
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: https://www.clamav.net/documents/potentially-unwanted-applications-pua .

Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Deleted files
Created processes
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.
UDP communications