startup.exe

DLsite Secure Application Kicker

Eisys Inc

This is a setup program which is used to install the application. The file has been seen being downloaded from www.dlsite.com.
Publisher:
EISYS,inc  (signed by Eisys Inc)

Product:
DLsite Secure Application Kicker

Version:
3.1.7.0

MD5:
c8fa69a7428ce378d7d5e05dd296a085

SHA-1:
fd5a282630b4dfbb23fa19daee3a5d013ec94a0b

SHA-256:
200e114e39517f202f151314f339da664cdea03f4fcbf29e1fd5ed4326d39ff6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 2:37:55 AM UTC  (today)

File size:
481.1 KB (492,688 bytes)

Product version:
3.1.7.0

Copyright:
Copyright (C) 2011-2013 EISYS,inc All rights reserved.

Original file name:
startup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\dlsite\gameprotection\upatecache\startup.exe\startup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/11/2013 1:13:20 AM

Valid to:
4/8/2016 1:44:42 AM

Subject:
E=infra@dlsite.com, CN=Eisys Inc, O=Eisys Inc, L=Chiyoda, S=Tokyo, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112107CBD1F9CA69D60690960351C5C6E1CF

File PE Metadata
Compilation timestamp:
2/19/2014 3:04:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:NWehwZjmZdCaXQ+6LYBOOjlsDVwvTvt5D:NWeSZaXQ+WYBOUiCLtN

Entry address:
0x1000

Entry point:
68, 01, 50, 50, 00, E8, 01, 00, 00, 00, C3, C3, B2, 16, D5, 09, 24, 37, 03, A3, 98, 8E, 54, 9A, 1E, 41, 21, A1, 66, 87, 34, 8E, C5, 16, C6, 68, 31, 30, E6, 02, ED, E2, 98, DD, 08, EA, E1, 5E, 98, 8B, 99, 33, 0D, 0E, 69, FF, 6D, EF, 0F, 34, AB, 30, DB, 4A, CD, F0, 29, A2, 31, AC, 53, C2, D6, 4D, 41, 3C, B2, 80, 99, A2, AE, 31, 24, 7E, 86, B2, E4, DC, 20, 49, 1D, FC, CA, B8, 41, 04, DF, E8, 11, 3A, 25, 82, 8A, F3, FB, B9, FD, 61, D9, 29, 48, 3F, 23, 80, 8E, 2D, D8, 12, 70, A3, 52, 86, 4A, 60, 6E, 08, 7E, 98...
 
[+]

Entropy:
7.9465

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
712 KB (729,088 bytes)

The file startup.exe has been seen being distributed by the following URL.

http://www.dlsite.com/modpub/cyphergame/autoupdate/.../startup_3.1.7.0.exe

Scan startup.exe - Powered by Reason Core Security