ezClear.exe

BlueZone

Rocket Software, Inc.

Publisher:
Rocket Software, Inc.   (signed by Rocket Software, Inc.)

Product:
BlueZone

Description:
BlueZone Web-to-Host Clear Utility

Version:
6.1.4

MD5:
a8b192d83c651f4851a5d7b54939c084

SHA-1:
639b82c77b8e5308b617380560f1e71550b22fdc

SHA-256:
370af1fc3ec3b7b9d4aa62021458e742d3f8a0e9b4dbc577090dca5ba9352df8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/8/2024 9:55:27 AM UTC  (today)

File size:
93.6 KB (95,840 bytes)

Product version:
6.1.4

Copyright:
© Rocket Software, Inc. 1996 - 2013. All rights reserved.

Trademarks:
BlueZone (tm)

Original file name:
ezClear.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\ezclear.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/30/2012 7:00:00 PM

Valid to:
12/9/2014 5:59:59 PM

Subject:
CN="Rocket Software, Inc.", OU=Secure Application Development, O="Rocket Software, Inc.", L=Waltham, S=Massachusetts, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0AA5EE77C9419093AEE2B94BE8F6905B

File PE Metadata
Compilation timestamp:
8/2/2013 7:06:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:MWM+dbJiBp+RRKT2IhN/hPkah2ZtYW74D5:hMWgaePH2tYX5

Entry address:
0x739F

Entry point:
E8, 32, 19, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 30, 3B, 41, 00, 89, 0D, 2C, 3B, 41, 00, 89, 15, 28, 3B, 41, 00, 89, 1D, 24, 3B, 41, 00, 89, 35, 20, 3B, 41, 00, 89, 3D, 1C, 3B, 41, 00, 66, 8C, 15, 48, 3B, 41, 00, 66, 8C, 0D, 3C, 3B, 41, 00, 66, 8C, 1D, 18, 3B, 41, 00, 66, 8C, 05, 14, 3B, 41, 00, 66, 8C, 25, 10, 3B, 41, 00, 66, 8C, 2D, 0C, 3B, 41, 00, 9C, 8F, 05, 40, 3B, 41, 00, 8B, 45, 00, A3, 34, 3B, 41, 00, 8B, 45, 04, A3, 38, 3B, 41, 00, 8D, 45, 08, A3, 44, 3B, 41, 00, 8B...
 
[+]

Entropy:
5.8584

Code size:
52 KB (53,248 bytes)

The file ezClear.exe has been seen being distributed by the following 3 URLs.

http://es3270.es.ci.la.ca.us/3270/.../ezclear.v61.exe

Scan ezClear.exe - Powered by Reason Core Security