s4client.exe

Project S4

GAMEON Studio Co.Ltd.

This is a setup program which is used to install the application. The file has been seen being downloaded from www87.zippyshare.com and multiple other hosts.
Publisher:
GAMEON Studio Co.Ltd.  (signed and verified)

Product:
Project S4

Description:
Project S4 Client.exe

Version:
0, 8, 32, 96313

MD5:
ca4d45bd5793b61f77c20ae7e5fc178a

SHA-1:
9a279f3dba4b6397be98ec67afbd45286112c2ee

SHA-256:
122923dc4b26ca89c19d1b03b94abff5f0c3df661377eb880b12c009931b858b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 5:28:32 AM UTC  (today)

File size:
10.5 MB (11,000,080 bytes)

Product version:
0, 8, 32, 96313

Copyright:
Copyright (C) 2007 Pentavision All rights reserved.

Original file name:
Client.exe

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/22/2015 2:00:00 AM

Valid to:
2/20/2017 1:59:59 AM

Subject:
CN=GAMEON Studio Co.Ltd., O=GAMEON Studio Co.Ltd., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0760555CC3719158DD98AB94B457777D

File PE Metadata
Compilation timestamp:
5/12/2016 8:19:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
196608:T4rClbJRSQF5Z4YJJsYRGe3qbZR0ve6EcIP6teY77j3gEshosuyaM+J4ZT:0rZu3fHsYRGGW1yteYHnsayV3

Entry address:
0x2165000

Entry point:
51, B9, 06, 00, 00, 00, 85, C9, 74, 28, 01, C8, D3, E0, 05, 45, 45, 53, 04, 50, E8, 00, 00, 00, 00, 83, 04, 24, 16, 8B, 04, 24, 83, C0, 09, C7, 80, CA, FF, FF, FF, 00, 00, 00, 00, FF, E0, 49, EB, D4, 59, E9, CE, 00, 00, 00, 55, 89, E5, 81, EC, 1C, 08, 00, 00, 60, C7, 45, FA, 00, 00, 00, 00, C7, 85, E8, FB, FF, FF, 00, 00, 00, 00, 31, DB, 8B, 85, E8, FB, FF, FF, 40, 89, 85, E8, FB, FF, FF, 81, BD, E8, FB, FF, FF, 00, 04, 00, 00, 74, 18, 8B, 85, EC, FB, FF, FF, 8D, 8D, F0, FB, FF, FF, 88, 04, 0B, FF, 85, EC...
 
[+]

Entropy:
7.9485  (probably packed)

Code size:
16.1 MB (16,910,848 bytes)

The file s4client.exe has been seen being distributed by the following 4 URLs.

http://www87.zippyshare.com/d/qbJrwO4q/.../dh l asasy xD.exe

Scan s4client.exe - Powered by Reason Core Security