sframe.exe

Gala Lab Corp.

Publisher:
Gala Lab Corp.  (signed and verified)

MD5:
431d7c983276f77e9aa95a34db0d56f4

SHA-1:
15c9e6c83f40574f3f33af9b5f69605dbfa29a18

SHA-256:
aafea376fb03717620c12a8c31703b8ec3ad7f9efdc199d0e78c14fc8a18f7a3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:33:04 PM UTC  (today)

File size:
4 MB (4,204,104 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\gpotato.eu\rappelz\sframe.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/23/2012 2:00:00 AM

Valid to:
8/24/2014 1:59:59 AM

Subject:
CN=Gala Lab Corp., OU=Tech Support Headquarters, O=Gala Lab Corp., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0DF9EE3CFBC6D8DEE0777F9263CE06DF

File PE Metadata
Compilation timestamp:
3/11/2013 6:47:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:ncgiduIdZjjDH+y8O5tmP11wu0KfJxf8v8bAcFFnRYVgNYc4lEViO140:nedPdNP+y8O5E1eQL8v8bASRYe7cEVa0

Entry address:
0x1000

Entry point:
68, 01, 40, E3, 00, E8, 01, 00, 00, 00, C3, C3, 52, 88, 88, FD, 1B, 98, C7, AA, CE, F6, 27, 69, 40, 6A, B0, C4, 94, E4, 6B, 1F, 99, B0, 59, 5C, 8B, CD, 13, 8C, 9C, E1, F6, 8F, 61, 6B, DE, DF, 85, E7, D6, 53, 4B, 58, AC, 5D, 34, 01, B7, C9, CB, 2E, 76, 14, B7, 0E, 35, F6, 6D, 6B, 6A, 44, 63, B1, 4D, B3, 5F, 4D, 1E, 86, 24, C6, 21, D7, FC, 9B, 81, A5, D0, 16, 53, 40, 75, 50, 4D, 22, 6E, E7, F7, 3B, E8, F8, 3D, 57, 1E, C1, F6, B6, 32, A8, B6, 54, 85, 15, D6, C5, 1C, 25, BE, CD, B4, 1A, 01, 26, DC, 4F, 90, B4...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
6.7 MB (7,016,448 bytes)

The file sframe.exe has been discovered within the following program.

Rappelz  by gPotato
de.rappelz.gpotato.eu
About 2% of users remove it
 
Powered by Should I Remove It?

Scan sframe.exe - Powered by Reason Core Security