farcry2_activation.exe

SecuROM Matroschka

Sony DADC Austria AG

Publisher:
Sony DADC Austria AG  (signed and verified)

Product:
SecuROM Matroschka

Description:
SecuROM Matroschka Unpacker

Version:
1.2.5.0

MD5:
bcf9741261e0197cd5f33ae460d1c8fa

SHA-1:
daa390c39aa206372bf48655b2ce058afce549d3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:38:15 PM UTC  (today)

File size:
4.9 MB (5,104,984 bytes)

Product version:
1.2.5.0

Copyright:
Copyright (C) 2008

Original file name:
Matroschka Unpacker

File type:
Executable application (Win32 EXE)

Language:
Almanca (Avusturya)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\farcry2_activation.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/16/2008 3:00:00 AM

Valid to:
10/13/2011 2:59:59 AM

Subject:
CN=Sony DADC Austria AG, OU=Virtual Factory, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sony DADC Austria AG, L=Salzburg, S=Salzburg, C=AT

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4BE2BE3FDD8463E4838F72B82732B8EC

File PE Metadata
Compilation timestamp:
9/16/2008 6:10:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
98304:70bB4sT62mkoGZEa2cprBCaIgf4PMiTofvhjio67kr2Si+osANJ1vz+B:ALT62fLKILCvgg0iTGpqL1vE

Entry address:
0x63EA60

Entry point:
B8, 89, FE, FF, FF, 8B, 84, 04, 77, 01, 00, 00, A3, A8, 57, D9, 00, 89, 25, AC, 57, D9, 00, E8, 06, 00, 00, 00, 7A, 7A, B5, A3, 00, C2, EB, 00, 81, 04, 24, 41, 00, 00, 00, 83, E0, FF, FF, 34, 24, 83, C9, 00, 81, 2C, 24, 40, 00, 00, 00, 57, 8B, 7C, 24, 04, EB, 00, 87, 3C, 24, 87, 0C, 24, 8B, 09, 83, E9, 11, 87, 0C, 24, 90, C7, 44, 24, 04, C2, 04, 00, 74, EB, FA, DD, A8, A3, 68, 58, D9, 00, 83, 3D, 68, 58, D9, 00, 00, 9C, 9C, 83, EC, 20, C7, 44, 24, 1C, D0, 0E, E3, BC, C7, 44, 24, 18, 6F, 00, 00, 00, 89, 6C...
 
[+]

Code size:
6.7 MB (6,979,584 bytes)

Scan farcry2_activation.exe - Powered by Reason Core Security