woool.dat.update

GameClient.exe

Shanda Games

Publisher:
SNDA Corporation  (signed by Shanda Games)

Product:
GameClient.exe

Description:
WW2 Client

Version:
8, 33, 0, 98

MD5:
50f924dafdedb920be7bc17ab9d2e20a

SHA-1:
2e0524429af8c6ac987cffbe030b8559d8d1e2c9

SHA-256:
bb34fdf466704b5080f9648abbf8cc3220096dd3e12c01b5fad15044251d0914

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:22:17 PM UTC  (today)

File size:
5.6 MB (5,883,288 bytes)

Product version:
1, 9, 9, 9

Copyright:
Copyright(C) 2007 SNDA Corporation.All rights reserved

Original file name:
GameClient.exe

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\woool client\data\woool.dat.update

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/26/2010 12:00:00 AM

Valid to:
11/25/2013 11:59:59 PM

Subject:
CN=Shanda Games, OU=Netwrok Security, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Shanda Games, L=ShangHai, S=ShangHai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
022893618A1DFA73D66C50FE4EE6DE61

File PE Metadata
Compilation timestamp:
6/20/2012 9:00:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:k2x1LOBgBFcllOMa8CAJXbGTRpX3+ewHrOXU:ZxFOuBFco85hGTRpH++k

Entry address:
0x3D88B4

Entry point:
E8, A6, 2D, 01, 00, E9, 16, FE, FF, FF, 6A, 14, 68, C8, 08, 91, 00, E8, 56, F2, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, B9, D7, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 4C, F2, 00, 00, C2, 10, 00, 6A, 0C, 68, E8, 08, 91, 00, E8, F8, F1, 00, 00, 83, 65, E4, 00, 8B, 75, 0C, 8B, C6, 0F, AF, 45...
 
[+]

Entropy:
6.6532

Code size:
4.4 MB (4,595,712 bytes)

Scan woool.dat.update - Powered by Reason Core Security