tera.exe

TERA

En Masse Entertainment

This is a setup program which is used to install the application. The file has been seen being downloaded from patch.tera.enmasse-game.com.
Publisher:
Bluehole Studio  (signed by En Masse Entertainment)

Product:
TERA

Description:
The Exiled Realm of Arborea

Version:
2.0.1.1

MD5:
bdcec62a76157c0273cbd3615b1ddfa0

SHA-1:
7ac769ea31342dbe66aaa26f88a1b74ff01d0e9f

SHA-256:
660716c841ee4d133431ce969025e03dea29dccd0f8a279b091ab085cf6d08aa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 7:05:42 PM UTC  (today)

File size:
11.4 MB (12,000,600 bytes)

Product version:
2.0.1.1

Copyright:
Copyright (C) 2014 Bluehole Studio

Original file name:
TERA

File type:
Executable application (Win32 EXE)

Language:
Koreanski (Korea)

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/3/2015 1:00:00 AM

Valid to:
4/6/2017 1:59:59 AM

Subject:
CN=En Masse Entertainment, O=En Masse Entertainment, L=Seattle, S=Washington, C=US

Issuer:
CN=thawte SHA256 Code Signing CA - G2, O="thawte, Inc.", C=US

Serial number:
1E52BBF5C90EC164D05BE0E41661525F

File PE Metadata
Compilation timestamp:
2/23/2016 2:28:45 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
196608:HhXE8WF3QmrDbwMcQhT5xNmYVsMsKDg9N/7330X9Z6Xz4+Wnyiiog6/FqB:HhXE8WNXbwMnrW/KDg9N/73et+WtixiC

Entry address:
0x2ADD000

Entry point:
52, 89, E2, 81, C2, 04, 00, 00, 00, 56, BE, 04, 00, 00, 00, 29, F2, 5E, 87, 14, 24, 5C, 89, 14, 24, C7, 04, 24, F4, 65, BF, 59, 81, 24, 24, 00, 29, DF, 77, FF, 0C, 24, 81, 34, 24, F7, 96, 97, 7F, C1, 24, 24, 05, 81, 34, 24, 00, C1, 16, C1, 83, EC, 04, 89, 34, 24, C7, 04, 24, 91, E8, F9, 37, F7, 14, 24, FF, 04, 24, FF, 04, 24, 51, B9, 91, E8, F9, 37, 01, 4C, 24, 04, 59, 52, C7, 04, 24, EB, 62, E7, 6F, 81, 2C, 24, 17, 94, F2, 7B, FF, 04, 24, 55, BD, 96, 9B, EE, 7F, 01, 6C, 24, 04, 5D, C1, 2C, 24, 04, 57, 68...
 
[+]

Code size:
26.4 MB (27,695,104 bytes)

The file tera.exe has been seen being distributed by the following URL.

Scan tera.exe - Powered by Reason Core Security