_start.exe

_geolib

Eversim

Publisher:
Eversim  (signed and verified)

Product:
_geolib

Description:
_geolib

Version:
1, 0, 0, 1

MD5:
18628cd44a422911f2023341b9364edd

SHA-1:
bbe499cc4db975111b2d62865dbd6fc9a88f918b

SHA-256:
f62d815d8edc930de5c8c79255ae05c71f6be58ac5ca66fc5315dd4727b9372e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:49:44 AM UTC  (today)

File size:
2 MB (2,080,960 bytes)

Product version:
0, 1, 2, 3

Copyright:
Copyright (C) 2014

Original file name:
_geolib.rc

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\Program Files\world of leaders\_start.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2013 1:00:00 AM

Valid to:
2/7/2015 12:59:59 AM

Subject:
CN=Eversim, O=Eversim, STREET=13 Place des Libertés Publiques, STREET=Immeuble le Mandinet II - Bat B, L=Lognes, S=Seine et Marne, PostalCode=77185, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EB979B2F13B48AE0530AEDCAA0A5B5C2

File PE Metadata
Compilation timestamp:
11/20/2014 5:15:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:Tpn9bHr8GwfRJ2o7CX4gEtEwmyx1zh46A1AUZoT:DUG20o7CytEwmSNFA1AU+

Entry address:
0xCBE6000

Entry point:
EB, 05, 13, 8D, B6, 4D, 01, 50, EB, 02, 3B, 6B, E8, 1B, 00, 00, 00, EB, 05, E1, 2E, 06, 38, 00, EB, 05, 5C, EF, 95, 68, 4C, 33, C0, EB, 04, B3, D9, 58, 73, 71, 5C, EB, 01, 72, EB, 03, CB, 3E, 8A, B8, 05, 48, FF, F6, EB, 01, F1, EB, 03, C2, 31, 20, 05, FB, B7, 00, 09, EB, 03, CC, 45, C1, 75, 3B, EB, 02, 76, 07, 64, FF, 30, EB, 01, D6, 64, 89, 20, EB, 04, 20, D1, 7B, 4F, EB, 01, 5C, 8B, 10, EB, 02, 21, 15, 64, 8F, 00, EB, 03, 72, 6D, B2, 83, C4, 04, EB, 02, 82, 23, 58, EB, 05, 0B, E4, D9, F6, EC, C3, EB, 05...
 
[+]

Code size:
3.6 MB (3,736,576 bytes)

Scan _start.exe - Powered by Reason Core Security