_start.exe

Eversim

Publisher:
Eversim  (signed and verified)

MD5:
be6b02e30bd3998ee5dc3bd20942876a

SHA-1:
17295dc7607c1c36b9425a6008a37a44d5d8e67c

SHA-256:
04ec9417d49f845dfb9714327d442ef53ece57e163900033ffb4b3418eaf5461

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 7:52:03 AM UTC  (today)

File size:
1.2 MB (1,228,616 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\elections 2012\_start.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/23/2012 1:00:00 AM

Valid to:
1/23/2013 12:59:59 AM

Subject:
CN=Eversim, O=Eversim, STREET=13 Place des Libertes Publiques, STREET=Immeuble Le Mandinet II - Bat B, L=Lognes, S=Marne-La-Vallée, PostalCode=77185, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E5B8E9A5285571B121B3C02C88BEC38B

File PE Metadata
Compilation timestamp:
2/6/2012 6:58:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:cA1pL3Bsgwf4bV8v/gwjy+mbFv4Poq1dPY+/41:cIFRCfRv/g7Zva7PY+

Entry address:
0x347A000

Entry point:
EB, 05, 3B, 59, 7B, E3, 51, 50, EB, 02, 87, D9, E8, 1B, 00, 00, 00, EB, 05, A7, 3D, 5F, FE, E5, EB, 05, C2, 71, DA, 24, D1, 33, C0, EB, 04, 92, 50, 4F, 94, 71, 5C, EB, 01, 9E, EB, 03, 9E, FA, DC, B8, 05, 48, E2, F6, EB, 01, C7, EB, 03, 24, EF, F6, 05, FB, B7, 1D, 09, EB, 03, 2A, 54, 12, 75, 3B, EB, 02, 5A, 39, 64, FF, 30, EB, 01, 7C, 64, 89, 20, EB, 04, 12, 19, 61, 63, EB, 01, F9, 8B, 10, EB, 02, 29, 2F, 64, 8F, 00, EB, 03, 4C, 0D, 49, 83, C4, 04, EB, 02, C0, C6, 58, EB, 05, BF, 37, 2B, 3D, 6A, C3, EB, 05...
 
[+]

Entropy:
7.9990  (probably packed)

Code size:
1.9 MB (1,957,888 bytes)

Scan _start.exe - Powered by Reason Core Security