hoi3_1.4.exe

HoI3 Patcher

Paradox Interactive

This is a setup program which is used to install the application. This is installed with multiple programs including Hearts of Iron III and For the Motherland version 3.05. The file has been seen being downloaded from s10615.chomikuj.pl and multiple other hosts.
Publisher:
Paradox Interactive

Product:
HoI3 Patcher

Version:
1.00.000

MD5:
c1744feb229ef2dbe6dfce29da29079d

SHA-1:
a676291d705825b6d45a5b25d4c395a5167d7b11

SHA-256:
88e596a46102f85da0d8bf65c3eef81b08e92817d92bc692ccbdae578b144d04

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:15:32 PM UTC  (today)

File size:
68.2 MB (71,486,651 bytes)

Product version:
1.00.000

Copyright:
Paradox Interactive

Original file name:
stub32i.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\hoi3_1.4.exe

File PE Metadata
Compilation timestamp:
9/5/2001 7:02:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:3dZ4tc/mg13ssUjGL0hdnoBbsklnKXtpGqp2WkJFV0gYK:QHg1csUxLHkJStpGqK1

Entry address:
0x8947

Entry point:
55, 8B, EC, 6A, FF, 68, 18, 33, 41, 00, 68, 80, BA, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, E8, 31, 41, 00, 33, D2, 8A, D4, 89, 15, 5C, 63, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 58, 63, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 54, 63, 41, 00, C1, E8, 10, A3, 50, 63, 41, 00, 33, F6, 56, E8, E0, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 11, 2F, 00, 00, FF, 15, EC, 31, 41, 00, A3, 24, 8A, 41, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
72 KB (73,728 bytes)

The file hoi3_1.4.exe has been discovered within the following programs.

For the Motherland version 3.05  by Paradox Interactive
www.paradoxplaza.com
About 4% of users remove it
Hearts of Iron III  by Paradox Development Studio
About 6% of users remove it
Semper Fi 2.04  by Paradox Interactive
About 4% of users remove it
 
Powered by Should I Remove It?

The file hoi3_1.4.exe has been seen being distributed by the following 6 URLs.

http://s10615.chomikuj.pl/File.aspx?e=CE5rnFLrBkS9c9mXw9WX93BfywRa6-4Y9YvplbTOY0qYL2-zc-jIzMxv8pdR-YZhZRKvvBa84M6DrXbKUMcAlhOOmhZrCBtEZ0eRy24NpqI7thulhxmAkd_e77fwNzqOArOjckCuByOmwnDjZHq2ew&pv=2

http://www.4players.de/services/.../download.php?action=start_now&DOWNLOADID=54978

Scan hoi3_1.4.exe - Powered by Reason Core Security