deme3b8.tmp

ESLAnticheat

Turtle Entertainment GmbH

It runs as a Windows 64-bit kernel mode device driver named “ESLAnticheat”.
Publisher:
<Turtle Entertainment>  (signed by Turtle Entertainment GmbH)

Product:
ESLAnticheat

Version:
1.0.0.74

MD5:
0af2c5fc14aaa87de3975a8e6042e45d

SHA-1:
9e796a580860fce443b941273ad5c1a58b3360e7

SHA-256:
694ff2100cea2f42e9ca070a1f0243794a43621a81cbec9b6e87333aa7888686

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 4:38:54 AM UTC  (today)

File size:
92.9 KB (95,168 bytes)

Product version:
1.0

Copyright:
Copyright © 2016

Original file name:
ESLAnticheat

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\deme3b8.tmp

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/12/2014 2:53:35 PM

Valid to:
1/26/2018 11:17:59 AM

Subject:
CN=Turtle Entertainment GmbH, O=Turtle Entertainment GmbH, L=Cologne, S=NRW, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A1E8F7E6944C92C7CA61440EFF3F250E

File PE Metadata
Compilation timestamp:
2/24/2017 10:52:24 AM

OS version:
10.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
14.0

Entry address:
0x1E877

Entry point:
E9, BC, DF, FF, FF, 0F, 85, 17, C2, FF, FF, 08, CD, E9, 02, D6, FF, FF, C4, 90, EE, 66, B2, F4, 36, E6, 1E, 78, F8, FA, 2A, 00, 7A, F0, 0E, F1, 33, FC, 7E, 5C, 8C, D1, 1F, EC, 3C, 08, 14, 9A, 80, 3A, 64, 1E, 66, EF, 11, ED, 07, 07, B9, 3F, 06, 15, CE, 42, F4, 24, 1F, 7F, ED, EB, 79, 5F, 89, 4D, A5, BC, 2C, 23, 7B, 94, DA, FD, 7D, 7A, FC, 27, 47, A6, FE, 8D, 8F, 70, 8E, 3D, 45, 3E, 62, 2B, 5B, C8, 2C, B7, CB, F0, C2, 34, 33, BC, D8, 87, D5, 5A, 74, AC, 56, 46, 9F, 8A, 5F, CA, 29, A5, 33, 4D, C4, A4, 7A, E7...
 
[+]

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
11 KB (11,264 bytes)

Driver
Display name:
ESLAnticheat

Type:
Kernel device driver (KernelDriver)


Scan deme3b8.tmp - Powered by Reason Core Security