beatwall_x64.dll

BeatWall.dll

Beijing Wen Ming Tian Xia Technologies Co., Ltd

It is installed as a Winsock Layered Service Provider (LSP) named “BeatWall over [MSAFD Tcpip [TCP/IP]]” as a layered chain entry.
Publisher:
Lofocus,inc.  (signed by Beijing Wen Ming Tian Xia Technologies Co., Ltd)

Product:
BeatWall.dll

Description:
BeatTrojan Personal FireWall dll library

Version:
3, 0, 0, 1

MD5:
d6092622453e08a55cb3547a072388be

SHA-1:
4884139dba1652a4a3d7ab7555044122c7147eab

SHA-256:
f2a0c661d8b2be558f944b5f300c52a9026a9795c34acf0e1a82983adcff4497

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/3/2026 12:23:45 AM UTC  (today)

File size:
401.2 KB (410,872 bytes)

Product version:
3, 0, 0, 1

Copyright:
CopyRight (c) www.lofocus.com 2005-2013

Original file name:
BeatWall.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\beattrojansecuritysuitev8\beattrojanwallv4\beatwall_x64.dll

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/15/2014 8:00:00 AM

Valid to:
10/15/2016 7:59:59 AM

Subject:
CN="Beijing Wen Ming Tian Xia Technologies Co., Ltd", O="Beijing Wen Ming Tian Xia Technologies Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7F1B3F031CC51BFB489472B2F00402E9

File PE Metadata
Compilation timestamp:
5/19/2014 11:07:35 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:2xLlU8HMHPKhGjZ+6mcpajpHS2fGQzQQDPEd11R1k4i3vUU9TBDcg148:2xJU8HMHPKUjZ+b5nuQXPRcU9TH1

Entry address:
0x2A918

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, D7, 74, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, AB, FE, FF, FF, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48, 83, EC, 40, 49, 8B, F1, 41, 8B, F8, 4C, 8B, E2, 48, 8B, D9, 83, EF, 01, 89, 7C, 24, 70, 78, 0F, 49, 2B, DC, 48, 89, 5C, 24, 60, 48, 8B, CB, FF, D6, EB, E8, EB, 00, 48, 8B, 5C...
 
[+]

Entropy:
5.9585

Code size:
283 KB (289,792 bytes)

Winsock2 LSP
Name:
BeatWall over [MSAFD Tcpip [TCP/IP]]

Type:
Layered Chain Entry

Provider ID:
{9C39B133-F6DC-42EF-B969-568DB50DCF06}

Service flags:
0x66


Scan beatwall_x64.dll - Powered by Reason Core Security