demoplay.exe

Noviy Disk, ZAO

Publisher:
Noviy Disk, ZAO  (signed and verified)

MD5:
d3add27543acbd540347dd50507430cf

SHA-1:
904f449808d7649dbbc4fe45278481ee117cb0e4

SHA-256:
ca67f0488bd5555634097fb3ebdc1b09a87f2fcf52585df569c4fe09a5071050

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 4:11:20 PM UTC  (today)

File size:
455.4 KB (466,376 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\w.i.t.c.h. ?????????\video\demoplay.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
9/26/2007 8:03:12 PM

Valid to:
9/25/2008 8:03:12 PM

Subject:
CN="Noviy Disk, ZAO", OU=Secure Application Development, O="Noviy Disk, ZAO", L=Moscow, S=Russia, C=RU

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
640D385D037262A34488E63ABDD66DF2

File PE Metadata
Compilation timestamp:
4/9/2008 7:36:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:26aiqek9rM3Hpbk/4LRJ+UC9XuWN/xphq:2oC9EHpbq4SNrN/xphq

Entry address:
0x6077C

Entry point:
55, 8B, EC, 83, C4, E8, 33, C0, 89, 45, EC, 89, 45, E8, B8, 5C, F6, 45, 00, E8, CC, 62, FA, FF, 33, C0, 55, 68, 0B, 08, 46, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, B8, 01, 00, 00, 00, E8, AD, 2A, FA, FF, 8B, 45, E8, 8D, 55, EC, E8, 36, 7F, FA, FF, 83, 7D, EC, 00, 74, 30, A1, 78, 2B, 46, 00, 8B, 00, E8, 58, A5, FF, FF, 8B, 0D, 7C, 2C, 46, 00, A1, 78, 2B, 46, 00, 8B, 00, 8B, 15, D4, DB, 45, 00, E8, 58, A5, FF, FF, A1, 78, 2B, 46, 00, 8B, 00, E8, 84, A6, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 12, 08, 46...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
381 KB (390,144 bytes)

Scan demoplay.exe - Powered by Reason Core Security