xr_3da.exe

GSC Game World

Publisher:
GSC Game World  (signed and verified)

MD5:
5e942279a45f03448bc567a408119579

SHA-1:
edcc12bbc788497e21f3fce22cbfc22bede38042

SHA-256:
e02f52c39d570a6ebce455d090942247882cbbd06bc2e3c2f018d301cf5b7a38

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/16/2024 12:35:20 PM UTC  (today)

Scan engine
Detection
Engine version

McAfee
Artemis!5E942279A45F
5600.6803

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15404

Trend Micro House Call
Suspicious_GEN.F47V0401
7.2.96

File size:
2.1 MB (2,227,504 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
3/24/2015 9:48:14 AM

Valid to:
3/23/2017 9:48:14 AM

Subject:
E=admin@gsc-game.com, CN=gsc-game.com, OU=TOV MIR IGR, O=GSC Game World, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
4BA0D219E39C3B8C593F253918172027

File PE Metadata
Compilation timestamp:
2/27/2008 6:49:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:LeWBRvOCH//q9jI1HE+380hMX1YhVznywrAS:aWBssc+380hQ+VzyGAS

Entry address:
0x1932EE

Entry point:
53, 51, 52, 56, 57, 55, 8B, EC, 81, EC, 00, 10, 00, 00, C7, 45, 80, EC, 4A, 59, 00, 8B, 75, 80, B9, C0, 00, 00, 00, 8D, BD, 80, FC, FF, FF, F3, A5, 8D, 85, 80, FC, FF, FF, 89, 85, 74, FC, FF, FF, C7, 85, 44, FC, FF, FF, 35, 2A, 71, 2F, 8B, 85, 44, FC, FF, FF, 89, 85, 1C, FC, FF, FF, 8B, 85, 74, FC, FF, FF, 89, 85, 28, FC, FF, FF, B8, 00, 03, 00, 00, C1, E8, 02, 89, 85, 24, FC, FF, FF, 83, BD, 24, FC, FF, FF, 00, 7E, 4E, 8B, 85, 28, FC, FF, FF, 8B, 00, 89, 85, 20, FC, FF, FF, 8B, 85, 28, FC, FF, FF, 8B, 00...
 
[+]

Entropy:
7.3232

Code size:
812 KB (831,488 bytes)

Scan xr_3da.exe - Powered by Reason Core Security