weshell_tgi.exe

Warrior Epic Launcher

True Games Interactive

Publisher:
True Games Interactive  (signed and verified)

Product:
Warrior Epic Launcher

Version:
1, 0, 0, 1

MD5:
24ce37809f8c58454cd040a674051694

SHA-1:
d19dd9e3175b97774244629c9b62cca013e4ea87

SHA-256:
d8d15f960135208e453e7faad644ced74c9cb7aebe29ee7f390d86143224a989

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:41:10 AM UTC  (today)

File size:
7.6 MB (7,938,600 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright 2009 True Games Interactive.All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\weshell_tgi.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
4/8/2009 8:00:00 AM

Valid to:
4/9/2010 7:59:59 AM

Subject:
CN=True Games Interactive, O=True Games Interactive, STREET=5 Peters Canyon, STREET=STE 360, L=Irvine, S=CA, PostalCode=92606, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
7A37839D4F9A95D19C229F493E209E81

File PE Metadata
Compilation timestamp:
1/8/2010 10:00:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:AYo5ebF6J/vq7blcGUTPrZSAqIf+aUsBvtlr36iY9ZBR5eEn3gYIlh:A3CQ8OnqIf1Usllm5ZBTl3ZIlh

Entry address:
0x549EA

Entry point:
E8, E0, 47, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 10, 75, 20, E8, 9F, 57, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 27, 57, 00, 00, 83, C4, 14, 83, C8, FF, E9, A1, 00, 00, 00, 8B, 45, 0C, 56, 8B, 75, 08, 3B, C3, 74, 21, 3B, F3, 75, 1D, E8, 70, 57, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, F8, 56, 00, 00, 83, C4, 14, 83, C8, FF, EB, 74, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 3D, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF, FF, FF...
 
[+]

Entropy:
6.9925

Code size:
1 MB (1,070,080 bytes)

Scan weshell_tgi.exe - Powered by Reason Core Security