_start.exe

_geolib

Eversim

Publisher:
Eversim  (signed and verified)

Product:
_geolib

Description:
_geolib

Version:
1, 0, 0, 1

MD5:
6551e1ffca0f2703da6a6856c276deb1

SHA-1:
11bd34ec561d057135f4400e915b88870c4a160d

SHA-256:
6a6aa773f7d7fa498bad3c8a73bc82c3f44a98532e59d35aac8750423f5e271f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:53:55 AM UTC  (today)

File size:
5.2 MB (5,498,352 bytes)

Product version:
5, 31, 0, 0

Copyright:
Copyright (C) 2014

Original file name:
_geolib.rc

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\Program Files\steam\steamapps\common\masters of the world\_start.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2013 1:00:00 AM

Valid to:
2/7/2015 12:59:59 AM

Subject:
CN=Eversim, O=Eversim, STREET=13 Place des Libertés Publiques, STREET=Immeuble le Mandinet II - Bat B, L=Lognes, S=Seine et Marne, PostalCode=77185, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EB979B2F13B48AE0530AEDCAA0A5B5C2

File PE Metadata
Compilation timestamp:
4/3/2014 10:49:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:Qu9Lx6Wagn/txS3nAw0XVig+3sDlitoFHEh0CMJcYfs3A3fMb:NMgVxS3Awlg+c5igEmHp9fMb

Entry address:
0x4F80D000

Entry point:
EB, 05, 73, EC, CF, B9, BD, 50, EB, 02, 2A, FD, E8, 1B, 00, 00, 00, EB, 05, 6C, 55, 05, 1B, 2D, EB, 05, FE, 66, 14, 18, 4D, 33, C0, EB, 04, C9, EB, 01, 8D, 71, 5C, EB, 01, 0F, EB, 03, 92, F8, 5A, B8, 05, 48, E9, F6, EB, 01, 5D, EB, 03, 90, D2, F2, 05, FB, B7, 16, 09, EB, 03, 20, DE, 2F, 75, 3B, EB, 02, 35, 40, 64, FF, 30, EB, 01, 8B, 64, 89, 20, EB, 04, BD, A2, AA, E0, EB, 01, E3, 8B, 10, EB, 02, D0, 1B, 64, 8F, 00, EB, 03, D6, 21, 66, 83, C4, 04, EB, 02, D8, 10, 58, EB, 05, 76, 6E, A9, 81, EE, C3, EB, 05...
 
[+]

Code size:
10.7 MB (11,237,888 bytes)

Windows Firewall Allowed Program
Name:
masters of the world


Scan _start.exe - Powered by Reason Core Security