EzQ.exe

EzQ Engine 7.0

EZNIX Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DB Messenger’.
Publisher:
EZNIX. Inc  (signed by EZNIX Inc.)

Product:
EzQ Engine 7.0

Version:
7.0.0.42

MD5:
bc6c36cf5d919742d51a474f9c8902d3

SHA-1:
3c3954a4ec910685feabba9e72eb3014a54fd840

SHA-256:
e3a34f418f42b41b605adee5daec1c010bb15d6342008360e38f5d1ba117311b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 3:07:40 AM UTC  (today)

File size:
11.3 MB (11,828,808 bytes)

Product version:
7.0.0.0

Copyright:
EZNIX. Inc

Trademarks:
EzQ Engine 7.0

Original file name:
EzQ.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/16/2012 9:00:00 AM

Valid to:
12/10/2014 8:59:59 AM

Subject:
CN=EZNIX Inc., O=EZNIX Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73E78017A7BF71B6762A603DC41FB6B5

File PE Metadata
Compilation timestamp:
10/5/2014 9:56:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:AzoQEzygx0XxDuMpVyEVcwaLfR1eZag05XTqHNPM5OCKNXAdaKuXTwCYAQf0Tq5c:nzygx0XZTzaLfrJTWN4OCK9ARu34Mv

Entry address:
0x6451B8

Entry point:
55, 8B, EC, B9, 19, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, B8, AC, F5, A3, 00, E8, 95, 2F, 9C, FF, 33, C0, 55, 68, 67, 57, A4, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 66, E2, 9B, FF, 8B, 45, EC, BA, 80, 57, A4, 00, E8, 91, 09, 9C, FF, 0F, 85, E7, 00, 00, 00, A1, 2C, 80, A6, 00, 8B, 00, E8, 9B, 5D, A4, FF, A1, 2C, 80, A6, 00, 8B, 00, BA, 90, 57, A4, 00, E8, 42, 58, A4, FF, 8D, 55, E0, A1, 2C, 80, A6, 00, 8B, 00, E8, 3B, 66, A4, FF, 8B, 45, E0, 8D, 55, E4, E8, B4, 78, 9C, FF...
 
[+]

Entropy:
6.5883

Developed / compiled with:
Microsoft Visual C++

Code size:
6.3 MB (6,571,520 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DB Messenger

Command:
"C:\db messenger\ezq.exe"


Scan EzQ.exe - Powered by Reason Core Security