× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ace939e348ad4fdf900d616a76a08a8e159bc69b3883aa52981eaa4ce04c5128
File name: MM3_Setup.exe
Detection ratio: 0 / 62
Analysis date: 2017-06-22 21:29:41 UTC ( 1 year, 4 months ago ) View latest
Antivirus Result Update
Ad-Aware 20170622
AegisLab 20170622
AhnLab-V3 20170622
Alibaba 20170622
ALYac 20170622
Antiy-AVL 20170622
Arcabit 20170622
Avast 20170622
AVG 20170622
Avira (no cloud) 20170622
AVware 20170622
Baidu 20170622
BitDefender 20170622
Bkav None
CAT-QuickHeal 20170622
ClamAV 20170622
CMC 20170619
Comodo 20170622
CrowdStrike Falcon (ML) 20170420
Cyren 20170622
DrWeb 20170622
Emsisoft 20170622
Endgame 20170615
ESET-NOD32 20170622
F-Prot 20170622
F-Secure 20170622
Fortinet 20170622
GData 20170622
Ikarus 20170622
Sophos ML 20170607
Jiangmin 20170622
K7AntiVirus 20170622
K7GW 20170622
Kaspersky 20170622
Kingsoft 20170622
Malwarebytes 20170622
McAfee 20170622
McAfee-GW-Edition 20170622
Microsoft 20170622
eScan 20170622
NANO-Antivirus 20170622
nProtect 20170622
Palo Alto Networks (Known Signatures) 20170622
Panda 20170622
Qihoo-360 20170622
Rising None
SentinelOne (Static ML) 20170516
Sophos AV 20170622
SUPERAntiSpyware 20170622
Symantec 20170622
Symantec Mobile Insight 20170621
Tencent 20170622
TheHacker 20170621
TotalDefense 20170622
TrendMicro 20170622
TrendMicro-HouseCall 20170622
Trustlook 20170622
VBA32 20170622
VIPRE 20170622
ViRobot 20170622
Webroot 20170622
WhiteArmor 20170616
Yandex 20170622
Zillya 20170622
ZoneAlarm by Check Point 20170622
Zoner 20170622
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright

Product MicroMP3
File version 1.0.3
Description MicroMP3 Setup
Comments This installation was built with Inno Setup.
Signature verification Signed file, verified signature
Signing date 7:10 PM 3/8/2014
Signers
[+] Open Source Developer, RealityRipple Software
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Certum Level III CA
Valid from 1:00 AM 11/15/2013
Valid to 1:00 AM 11/15/2014
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 80F5B69D9C2A4C504DC21BDAEC2C2DAC96A9C2CE
Serial number 78 3B E1 31 53 D3 39 9C AB 8A DF 68 E5 41 CE 3E
[+] Certum Level III CA
Status Valid
Issuer Certum CA
Valid from 1:53 PM 3/3/2009
Valid to 1:53 PM 3/3/2024
Valid usage All
Algorithm sha1RSA
Thumbprint 827E72353D6910A9DEC7F3D1061676E80356FD53
Serial number 04 7A 53
[+] Certum
Status Valid
Issuer Certum CA
Valid from 11:46 AM 6/11/2002
Valid to 11:46 AM 6/11/2027
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, OCSP Signing
Algorithm sha1RSA
Thumbprint 6252DC40F71143A22FDE9EF7348E064251B18118
Serial number 01 00 20
Counter signers
[+] Certum Time-Stamping Authority
Status Valid
Issuer Certum CA
Valid from 1:58 PM 3/3/2009
Valid to 1:58 PM 3/3/2024
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 0D2CF962FB4D042F2F1401DE66EACBA80DA76112
Serial number 04 7A 55
[+] Certum
Status Valid
Issuer Certum CA
Valid from 11:46 AM 6/11/2002
Valid to 11:46 AM 6/11/2027
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, OCSP Signing
Algorithm sha1RSA
Thumbrint 6252DC40F71143A22FDE9EF7348E064251B18118
Serial number 01 00 20
Packers identified
F-PROT INNO, UPX
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-01-30 14:21:56
Entry Point 0x000113BC
Number of sections 8
PE sections
Overlays
MD5 ccb18f06b3eb80cdc7f75a3d0f767829
File type data
Offset 190464
Size 1738096
Entropy 8.00
PE imports
RegCloseKey
OpenProcessToken
RegOpenKeyExW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegQueryValueExW
InitCommonControls
GetLastError
GetStdHandle
GetUserDefaultLangID
GetSystemInfo
GetModuleFileNameW
WaitForSingleObject
GetVersionExW
FreeLibrary
QueryPerformanceCounter
GetTickCount
GetThreadLocale
VirtualProtect
GetFileAttributesW
RtlUnwind
lstrlenW
GetExitCodeProcess
CreateProcessW
GetStartupInfoA
SizeofResource
GetWindowsDirectoryW
LocalAlloc
LockResource
GetDiskFreeSpaceW
GetCommandLineW
SetErrorMode
UnhandledExceptionFilter
LoadLibraryExW
MultiByteToWideChar
EnumCalendarInfoW
GetCPInfo
DeleteFileW
GetProcAddress
InterlockedCompareExchange
GetLocaleInfoW
lstrcpynW
RaiseException
WideCharToMultiByte
RemoveDirectoryW
SetFilePointer
GetFullPathNameW
ReadFile
GetEnvironmentVariableW
InterlockedExchange
CreateDirectoryW
WriteFile
GetCurrentProcess
CloseHandle
FindFirstFileW
GetACP
GetModuleHandleW
SignalObjectAndWait
SetEvent
FormatMessageW
LoadLibraryW
CreateEventW
GetVersion
LoadResource
FindResourceW
CreateFileW
VirtualQuery
VirtualFree
FindClose
TlsGetValue
Sleep
SetEndOfFile
TlsSetValue
ExitProcess
GetCurrentThreadId
VirtualAlloc
GetFileSize
SetLastError
ResetEvent
SysReAllocStringLen
SysFreeString
SysAllocStringLen
GetSystemMetrics
SetWindowLongW
MessageBoxW
PeekMessageW
LoadStringW
MessageBoxA
CreateWindowExW
MsgWaitForMultipleObjects
TranslateMessage
CharUpperBuffW
CallWindowProcW
CharNextW
GetKeyboardType
ExitWindowsEx
DispatchMessageW
DestroyWindow
Number of PE resources by type
RT_ICON 10
RT_STRING 6
RT_RCDATA 4
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 14
NEUTRAL 9
PE resources
ExifTool file metadata
SubsystemVersion
5.0

Comments
This installation was built with Inno Setup.

InitializedDataSize
124416

ImageVersion
6.0

ProductName
MicroMP3

FileVersionNumber
1.0.3.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

LinkerVersion
2.25

FileTypeExtension
exe

MIMEType
application/octet-stream

FileVersion
1.0.3

TimeStamp
2013:01:30 15:21:56+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
1.0.3

FileDescription
MicroMP3 Setup

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
RealityRipple Software

CodeSize
65024

FileSubtype
0

ProductVersionNumber
1.0.3.0

EntryPoint
0x113bc

ObjectFileType
Executable application

File identification
MD5 11d364e5932beb6ca4bf40898c981276
SHA1 00d07097cd16dff50aef5cca26fd21b6b4c1c47a
SHA256 ace939e348ad4fdf900d616a76a08a8e159bc69b3883aa52981eaa4ce04c5128
ssdeep
49152:mjOfPrKfp/8McWC8a0F/FbKEx+Hfjmu6SduBjAz5H2x4xfu/Q/S:zYTC+/F1+/jmuSW0KhC

authentihash e46e32b577aac9ee4f5cd6b53c5184a117a461f003126355c38e273f926a8a97
imphash 48aa5c8931746a9655524f67b25a47ef
File size 1.8 MB ( 1928560 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable Delphi generic (57.2%)
Win32 Executable (generic) (18.2%)
Win16/32 Executable Delphi generic (8.3%)
Generic Win/DOS Executable (8.0%)
DOS Executable Generic (8.0%)
Tags
peexe signed upx overlay

VirusTotal metadata
First submission 2014-08-01 22:58:48 UTC ( 4 years, 3 months ago )
Last submission 2017-06-23 21:59:42 UTC ( 1 year, 4 months ago )
File names ACE939E348AD4FDF900D616A76A08A8E159BC69B3883AA52981EAA4CE04C5128.exe
mm3_setup.exe
MM3_Setup.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Deleted files
Created processes
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.