crossfire.dll

Cong ty dau tu va phat trien cong nghe thong tin

Publisher:

MD5:
dd8b80a3da792aed42fa02afb2ec59be

SHA-1:
eb7399dfc7b700641153bc370216b642cbabd287

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/26/2024 8:43:49 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

Trend Micro House Call
TROJ_GEN.F47V0427
7.2.141

File size:
42.3 KB (43,336 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\vtcgame\dot kich\gpgame\crossfire.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/30/2013 7:00:00 AM

Valid to:
8/26/2015 6:59:59 AM

Subject:
CN=Cong ty dau tu va phat trien cong nghe thong tin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cong ty dau tu va phat trien cong nghe thong tin, L=Hanoi, S=Hanoi, C=VN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F318FA88A92CCE830CC187023EC0B36

File PE Metadata
Compilation timestamp:
4/23/2014 9:25:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:5qR7uR4XWBNQLn5A/JIKkPpWwz3qtuA5VtIgFhzn/uGNIf+FZvKkt:5q2HQA2Lowziu4bIyz6f0vt

Entry address:
0x2ED6

Entry point:
B8, 84, 7F, 01, 10, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 2F, 32, 07, F4, BA, A8, 75, 44, 9B, B5, C8, 6D, 01, 58, 00, 80, 1C, 2D, E1, A9, E5, E5, 7F, 93, BD, 7C, 05, 5E, BA, B5, 42, FD, AC, 57, 4F, E7, 88, 60, 5A, 15, C2, 49, E3, FB, 63, F6, A3, AC, 15, 15, 77, 0B, BB, DA, E8, A9, 36, CD, AB, 9D, 4D, 31, 5A, 7D, 04, CD, D1, A7, 2E, 07, D5, B5, 2C, DD, 81, B9, FE, C6, 33, 1E, 74, 18, BF, 9C, 25, 00, ED, 61, 87, 08, 71, 1C, 86...
 
[+]

Entropy:
7.8202

Packer / compiler:
PECompact v2

Code size:
48 KB (49,152 bytes)

Scan crossfire.dll - Powered by Reason Core Security