evtx_view64.exe

EventLog parser application

TZWORKS LLC

Publisher:
TZWORKS LLC  (signed and verified)

Product:
EventLog parser application

Description:
Windows Eventlog Viewer

Version:
0.0.6.5

MD5:
b686923d5c1680d098feacf39d817c96

SHA-1:
05eee7108d0c7dcbafe38ee94a8398ee648ee360

SHA-256:
ac86a1056a195769f952a4687c0d2d44cc5401ac2fb57c75f6d57407017e88c7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:22:31 AM UTC  (today)

File size:
1.5 MB (1,562,408 bytes)

Product version:
0.0.6.5

Copyright:
Copyright © TZWorks LLC 2009-2012

Original file name:
evtx_view.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\evtx_view64.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
5/28/2011 12:17:20 AM

Valid to:
5/28/2014 12:17:18 AM

Subject:
E=davet@tzworks.net, CN=TZWORKS LLC, OU=Software Engineering, O=TZWORKS LLC, L=Herndon, S=VA, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000013032F3AF87

File PE Metadata
Compilation timestamp:
4/5/2012 9:22:39 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:uNvvvdXSduiQnwUcC0gjgz4mdg8/8uQo/k:u5vod0nzk9dg8/8Lo/k

Entry address:
0xBF3D8

Entry point:
48, 83, EC, 28, E8, 33, B4, 00, 00, 48, 83, C4, 28, E9, 76, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 41, A2, 0A, 00, 75, 11, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 02, F3, C3, 48, C1, C9, 10, E9, A9, B4, 00, 00, CC, 40, 53, 48, 83, EC, 20, 49, 8B, C0, 4D, 85, C9, 74, 3B, 48, 85, C9, 75, 15, E8, 68, 1F, 00, 00, BB, 16, 00, 00, 00, 89, 18, E8, C8, B7, 00, 00, 8B, C3, EB, 23, 48, 85, C0, 74, E6, 49, 3B, D1, 73, 0C, E8, 49, 1F, 00, 00, BB...
 
[+]

Entropy:
6.1602

Code size:
931 KB (953,344 bytes)

Scan evtx_view64.exe - Powered by Reason Core Security