By using Saferwall you consent to our Terms of Service and Privacy Policy and allow us to share your submission with the security community. Learn more

Summary

Analyse score

0/ 13

No antivirus venders flagged
this file as malicious

Signature

Signed file, valid signature

Last scanned

First submission

File type

exe

exe

Basic properties

CRC32

0x6a9f4b08

MD5

5246ed1b888ef8f0949f79797795dcbd

Magic

PE32+ executable (GUI) x86-64, for MS Windows

SHA1

bc14d3ed8757802df241ac904d3188964b9b6963

SHA256

91341979158eab8218aac39ed10e724410d0004359e0b9059fdef8c37c6a2216

SHA512

4d7914997073c728edea6bb7b3da86f027ebe834cc16fe15528fc849d5c056303a510f82167d3811c31b0835970b801f614668c8990e52f0883b8189ee8fa42c

SSDeep

12288:QnH1UI5rFBbXKetCpAEORGJCkpj9xN0zWq/EN1AU:Y1UIL1XKetCBMG0k0Kqs7t

Size

1.03MB

TLSH

c3355d466acd9027d2f24b304af2a3205b7bbd917d355a1f219c728d6fb3e4c2d12b52

Packer
  • PE+(64): compiler: Microsoft Visual C/C++(2015 v.14.0)[-]
  • PE+(64): linker: Microsoft Linker(14.0, Visual Studio 2015 14.0*)[EXE64,signed]
TrID
  • 72.7% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
  • 13.2% (.EXE) Win64 Executable (generic) (10523/12/4)
  • 6.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
  • 2.5% (.EXE) OS/2 Executable (generic) (2029/13)
  • 2.5% (.EXE) Generic Win/DOS Executable (2002/3)
Tags

ExifTool File Metadata

CharacterSet

Unicode

CodeSize

84.50KB

CompanyName

Blizzard Entertainment, Inc.

EntryPoint

0x3b30

ExifToolVersionNumber

12.88

FileDescription

SC2Switcher

FileFlags

(none)

FileFlagsMask

0x0017

FileOs

Win32

FileSize

1083 kB

FileSubtype

0

FileType

Win64 EXE

FileTypeExtension

exe

FileVersion

5.0.13.92440

FileVersionNumber

5.0.13.26904

ImageFileCharacteristics

Executable, Large address aware

ImageVersion

0.0

InitializedDataSize

968.00KB

InternalName

SC2Switcher

LanguageCode

Neutral

LegalCopyright

© 2010-2024 Blizzard Entertainment, Inc.

LinkerVersion

14.0

MachineType

AMD AMD64

MimeType

application/octet-stream

ObjectFileType

Executable application

OriginalFileName

SC2Switcher.exe

OsVersion

5.2

PeType

PE32+

ProductName

SC2Switcher (Retail)

ProductVersion

Version 5.0.13.92440

ProductVersionNumber

5.0.13.26904

Subsystem

Windows GUI

SubsystemVersion

5.2

UninitializedDataSize

0

Submissions

Published Name Source Country
SC2Switcher_x64.exe web
N/A

Indicators

Description Severity Category Module
Resolves API dynamically at runtime to obfuscate functionality
high
Anti-Analysis behavior