rqlauncher.exe

LLC 1C Online Games

This is a setup program which is used to install the application. The file has been seen being downloaded from update.royalquest.ru.
Publisher:
LLC 1C Online Games  (signed and verified)

Description:
Royal Quests

Version:
0.0.0.19668

MD5:
4c37546a8ccab020fe061ff095f771e7

SHA-1:
436880314c7e81309ae07976aa6f8371038d0288

SHA-256:
cb518ccac694a2ca399ee24319979ff0cd6c82ba286a166c4fe0f411034b1827

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 10:43:46 AM UTC  (today)

File size:
5.2 MB (5,405,352 bytes)

Product version:
1.0.0.0

Copyright:
Katauri/1C (c) 2012

Original file name:
rqlauncher.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\1c\royal quest\rqlauncher.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/29/2015 7:00:00 AM

Valid to:
8/28/2016 6:59:59 AM

Subject:
CN=LLC 1C Online Games, OU=IT, O=LLC 1C Online Games, L=Moscow, S=Moscow, C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
439908F62CC95D4989D728DB027E1519

File PE Metadata
Compilation timestamp:
10/21/2015 3:09:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:E3z7WgGyANgr70lc9z032FzEo4yDRX47QRqqxfnyp8tVkjxdQ9IPcoCEzB0DmZi:Q7WgG9u/0Y7FzMroVkjxDCEzBkmZi

Entry address:
0x17C375

Entry point:
E8, EC, 03, 01, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 53, 33, DB, 56, 57, 39, 5D, 14, 75, 10, 3B, C3, 75, 10, 39, 5D, 0C, 75, 12, 33, C0, 5F, 5E, 5B, 5D, C3, 3B, C3, 74, 07, 8B, 7D, 0C, 3B, FB, 77, 13, E8, EA, 0E, 00, 00, 6A, 16, 5E, 89, 30, E8, DA, 35, 00, 00, 8B, C6, EB, DD, 39, 5D, 14, 75, 04, 88, 18, EB, D2, 8B, 55, 10, 3B, D3, 75, 04, 88, 18, EB, D9, 83, 7D, 14, FF, 8B, C8, 75, 13, 8B, F0, 2B, F2, 8A, 0A, 88, 0C, 16, 42, 3A, CB, 74, 22, 4F, 75, F3, EB, 1D, 8B, F2, 2B, F0, 8A, 14, 0E...
 
[+]

Code size:
2.8 MB (2,954,752 bytes)

The file rqlauncher.exe has been seen being distributed by the following URL.

Scan rqlauncher.exe - Powered by Reason Core Security