s4client.exe

Project S4

GAMEON Studio Co.Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from www106.zippyshare.com and multiple other hosts.
Publisher:
GAMEON Studio Co.Ltd.  (signed and verified)

Product:
Project S4

Description:
Project S4 Client.exe

Version:
0, 8, 32, 95923

MD5:
44f5b7fdea0058a0cb5766e5cbd343b1

SHA-1:
6b105756affc40e123a27534b5748fe92caf264f

SHA-256:
112422adf106210996bdf47fbec65519bf7033d207dc808a50e57045fde1e101

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 6:22:53 PM UTC  (today)

File size:
10.4 MB (10,940,176 bytes)

Product version:
0, 8, 32, 95923

Copyright:
Copyright (C) 2007 Pentavision All rights reserved.

Original file name:
Client.exe

File type:
Executable application (Win32 EXE)

Language:
Korean

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/22/2015 1:00:00 AM

Valid to:
2/20/2017 12:59:59 AM

Subject:
CN=GAMEON Studio Co.Ltd., O=GAMEON Studio Co.Ltd., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0760555CC3719158DD98AB94B457777D

File PE Metadata
Compilation timestamp:
4/14/2016 10:47:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
196608:gnqH/jOB93ZmHEJR51L6AUo3wRx2x5raqgaQBJfyOfPPghGmy:I4Slyy5b3acxBQBHfiy

Entry address:
0x2140000

Entry point:
51, B9, 06, 00, 00, 00, 85, C9, 74, 28, 01, C8, D3, E0, 05, 45, 45, 53, 04, 50, E8, 00, 00, 00, 00, 83, 04, 24, 16, 8B, 04, 24, 83, C0, 09, C7, 80, CA, FF, FF, FF, 00, 00, 00, 00, FF, E0, 49, EB, D4, 59, E9, CE, 00, 00, 00, 55, 89, E5, 81, EC, 1C, 08, 00, 00, 60, C7, 45, FA, 00, 00, 00, 00, C7, 85, E8, FB, FF, FF, 00, 00, 00, 00, 31, DB, 8B, 85, E8, FB, FF, FF, 40, 89, 85, E8, FB, FF, FF, 81, BD, E8, FB, FF, FF, 00, 04, 00, 00, 74, 18, 8B, 85, EC, FB, FF, FF, 8D, 8D, F0, FB, FF, FF, 88, 04, 0B, FF, 85, EC...
 
[+]

Code size:
16.1 MB (16,868,352 bytes)

The file s4client.exe has been seen being distributed by the following 2 URLs.

http://www106.zippyshare.com/d/V7PfTdO5/.../S4Client.exe

Scan s4client.exe - Powered by Reason Core Security