elsword.exe

KOG Co., Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from download2168.mediafire.com.
Publisher:
KOG Co., Ltd.  (signed and verified)

MD5:
9fb7e40d1b5655b88490ed3a8bfeb3d9

SHA-1:
5b74a11002a2c0450c19026fd5c3e14e12e72db6

SHA-256:
69c40b4268272f19d4c1fb41034b1e6ba2e902372c3fe2fdece1cb8dabff6d07

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 1:53:38 AM UTC  (today)

File size:
4.2 MB (4,353,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\elsword.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/22/2012 10:00:00 PM

Valid to:
12/22/2015 9:59:59 PM

Subject:
CN="KOG Co., Ltd.", OU=IT Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="KOG Co., Ltd.", L=Jung-gu, S=Daejeon, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
41BE384F5593EC6A5B0DE476368D3C99

File PE Metadata
Compilation timestamp:
7/1/2013 1:35:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:+pFG+a4oOPOBoJIjMP2nHpQ6M68kXB892vzDVMyBI27i2nHJr4B:8Zd3PO/Q2n+X9AZX7i2npr4B

Entry address:
0x1E345

Entry point:
E8, CE, 93, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, A0, C0, 51, 00, 89, 0D, 9C, C0, 51, 00, 89, 15, 98, C0, 51, 00, 89, 1D, 94, C0, 51, 00, 89, 35, 90, C0, 51, 00, 89, 3D, 8C, C0, 51, 00, 66, 8C, 15, B8, C0, 51, 00, 66, 8C, 0D, AC, C0, 51, 00, 66, 8C, 1D, 88, C0, 51, 00, 66, 8C, 05, 84, C0, 51, 00, 66, 8C, 25, 80, C0, 51, 00, 66, 8C, 2D, 7C, C0, 51, 00, 9C, 8F, 05, B0, C0, 51, 00, 8B, 45, 00, A3, A4, C0, 51, 00, 8B, 45, 04, A3, A8, C0, 51, 00, 8D, 45, 08, A3, B4, C0, 51...
 
[+]

Code size:
894.5 KB (915,968 bytes)

The file elsword.exe has been discovered within the following program.

Project64 1.6  by Project64
Publisher's description - “Project64 is a Nintendo 64 emulator for Windows by Zilmar, Jabo, Tooie and Witten. Project64 or PJ64 dates back to its first public release Project64 v1.0 in May 26th 2001. Project64 is an emulator designed to emulate a Nintendo64 video game system on a Microsoft Windows based PC.”
www.pj64.net
About 7% of users remove it
 
Powered by Should I Remove It?

The file elsword.exe has been seen being distributed by the following URL.

Scan elsword.exe - Powered by Reason Core Security