crossfire.dll

Cong ty dau tu va phat trien cong nghe thong tin

Publisher:

MD5:
dac355ee2b20a439bcb32e9095eae6e8

SHA-1:
fbd00f633ee653e5a75d0b92a0f1505864c5fa11

SHA-256:
ba97e72ea25a1e2c4d7c607d45b3ac63941c2ccf5b518e4ecd002d56bda08063

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/23/2024 10:24:31 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Bkav FE
HW32.CDB
1.3.0.4959

File size:
42.3 KB (43,336 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\vtcgame\dot kich\gpgame\crossfire.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/30/2013 7:00:00 AM

Valid to:
8/26/2015 6:59:59 AM

Subject:
CN=Cong ty dau tu va phat trien cong nghe thong tin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cong ty dau tu va phat trien cong nghe thong tin, L=Hanoi, S=Hanoi, C=VN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2F318FA88A92CCE830CC187023EC0B36

File PE Metadata
Compilation timestamp:
6/12/2014 5:32:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:g8QvlqRKKwlGP/Jm55QNa9pk4fdC6G39aO6wT4RKMCrOK99:g8Qvvj3HnHk4VBEaj5hCv9

Entry address:
0x2F26

Entry point:
B8, 88, 7F, 01, 10, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 91, 6C, F8, D7, 7F, DB, 08, C6, 28, 01, 3E, 50, 3D, 94, 73, E1, EB, AE, 68, 90, 97, D4, 81, BA, 7C, AA, 36, 36, 76, 34, 53, 6B, C4, DF, 0B, 1B, 53, F5, 2B, 6E, AD, B2, 5A, DD, EB, 4F, 0E, 15, EA, 3F, 87, 74, D0, 75, BF, E6, 7E, E9, E7, 2A, D6, AE, 3D, 08, CB, 82, F5, 12, DE, 1C, E3, DB, 38, A2, 4A, 2C, 7B, 77, 97, 35, C5, EA, A5, F4, B8, 8B, F0, 6E, CB, C7, 96, 25, 4B...
 
[+]

Packer / compiler:
PECompact v2

Code size:
48 KB (49,152 bytes)

Scan crossfire.dll - Powered by Reason Core Security