loadout.exe

Edge of Reality, Ltd.

This file is installed with the program Loadout.
Publisher:
Edge of Reality, Ltd.  (signed and verified)

MD5:
df23682bc3bf3470fd9d5c51b245f055

SHA-1:
e8e2a1cb61748298c573846fa4d4f99102ae6f44

SHA-256:
065bf9b07ef95a3e49199e2062c1851b352456cd0cfd8ab6c2b9ed109ae47548

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 8:48:46 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14302

File size:
16.1 MB (16,906,592 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\steam\steamapps\common\loadout\loadout.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/14/2013 8:00:00 PM

Valid to:
10/20/2015 8:00:00 AM

Subject:
CN="Edge of Reality, Ltd.", O="Edge of Reality, Ltd.", L=Austin, S=Texas, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F60AF6E488DADBBA691A0AA92990C62

File PE Metadata
Compilation timestamp:
3/3/2014 7:44:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:+G/NrhyAZz2bbKEIPJn0HPA65skpC4BCX9NHTcNFdv:+S2A8K/Z0Jk4BG9d+vv

Entry address:
0x28C52EE

Entry point:
53, 51, 52, 56, 57, 55, 8B, EC, 81, EC, 00, 10, 00, 00, C7, 45, 80, EC, 6A, CC, 02, 8B, 75, 80, B9, C0, 00, 00, 00, 8D, BD, 80, FC, FF, FF, F3, A5, 8D, 85, 80, FC, FF, FF, 89, 85, 74, FC, FF, FF, C7, 85, 44, FC, FF, FF, 7D, 58, 68, A6, 8B, 85, 44, FC, FF, FF, 89, 85, 1C, FC, FF, FF, 8B, 85, 74, FC, FF, FF, 89, 85, 28, FC, FF, FF, B8, 00, 03, 00, 00, C1, E8, 02, 89, 85, 24, FC, FF, FF, 83, BD, 24, FC, FF, FF, 00, 7E, 4E, 8B, 85, 28, FC, FF, FF, 8B, 00, 89, 85, 20, FC, FF, FF, 8B, 85, 28, FC, FF, FF, 8B, 00...
 
[+]

Entropy:
7.9905  (probably packed)

Code size:
8.4 MB (8,794,624 bytes)

The file loadout.exe has been discovered within the following program.

Loadout  by Edge of Reality
www.loadout.com
About 2% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP SSL):
Connects to ec2-54-241-9-230.us-west-1.compute.amazonaws.com  (54.241.9.230:443)

TCP:
Connects to ec2-54-215-6-254.us-west-1.compute.amazonaws.com  (54.215.6.254:5222)

TCP (HTTP):
Connects to ec2-54-207-222-13.sa-east-1.compute.amazonaws.com  (54.207.222.13:80)

TCP (HTTP):
Connects to ec2-54-207-204-242.sa-east-1.compute.amazonaws.com  (54.207.204.242:80)

TCP (HTTP):
Connects to ec2-54-207-182-105.sa-east-1.compute.amazonaws.com  (54.207.182.105:80)

TCP (HTTP):
Connects to ec2-54-207-178-242.sa-east-1.compute.amazonaws.com  (54.207.178.242:80)

TCP (HTTP):
Connects to ec2-54-207-167-0.sa-east-1.compute.amazonaws.com  (54.207.167.0:80)

TCP (HTTP):

TCP (HTTP):
Connects to 75.126.116.30-static.reverse.softlayer.com  (75.126.116.30:80)

TCP (HTTP):
Connects to 75.126.116.26-static.reverse.softlayer.com  (75.126.116.26:80)

TCP (HTTP):
Connects to 5.153.6.220-static.reverse.softlayer.com  (5.153.6.220:80)

TCP (HTTP):
Connects to 5.153.6.219-static.reverse.softlayer.com  (5.153.6.219:80)

TCP (HTTP):
Connects to 5.153.59.4-static.reverse.softlayer.com  (5.153.59.4:80)

TCP (HTTP):
Connects to 5.153.59.2-static.reverse.softlayer.com  (5.153.59.2:80)

TCP (HTTP):
Connects to 5.153.58.144-static.reverse.softlayer.com  (5.153.58.144:80)

TCP (HTTP):
Connects to 5.153.58.140-static.reverse.softlayer.com  (5.153.58.140:80)

TCP (HTTP):
Connects to 108.168.242.76-static.reverse.softlayer.com  (108.168.242.76:80)

Scan loadout.exe - Powered by Reason Core Security