Henzo.exe

IP Labs GmbH

Publisher:
HenzoXL  (signed by IP Labs GmbH)

Description:
Henzo

Version:
2.2.21.0

MD5:
6384e72f03d6722114f6a66d7a8dd7bf

SHA-1:
dac9c72e5a330c77bd8729fff4150694f47b1661

SHA-256:
9aef446a55430cd3c818c6d5f96d8993b6c37d2239db609b3c1ba22306c4a810

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 5:38:00 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.Wpbrutebot-2
0.98/19296

File size:
4.8 MB (5,080,216 bytes)

Product version:
2.2

Copyright:
Copyright (C) 2007 by IP Labs GmbH

Original file name:
Henzo.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\henzo\henzoxl\henzo.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/10/2009 2:00:00 AM

Valid to:
6/19/2010 1:59:59 AM

Subject:
CN=IP Labs GmbH, OU=APPLICATION DEVELOPMENT, O=IP Labs GmbH, L=Bonn, S=NRW, C=DE

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
34B9F8A2DE85D8919C6C0AF2E7434EDB

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:RSIdoMpMmJhLn9V9cZ/nI2WrWcrR9pMmNoIvOmmwoBXUYPPfb68tPzjm/TLW+ZFX:RbgmJhT9rl2MWcrtDPkPBXlPzjsLW+FR

Entry address:
0x3EE884

Entry point:
55, 8B, EC, 83, C4, F0, B8, 30, 74, 7E, 00, E8, 6C, 9C, C1, FF, 6A, 00, 33, C9, BA, 0C, E9, 7E, 00, B8, 1C, E9, 7E, 00, E8, 0D, 08, F5, FF, 84, C0, 74, 52, A1, 44, 18, 80, 00, 50, A1, F8, 61, 7C, 00, 50, A1, B0, AA, 7C, 00, 50, 6A, 05, 6A, 00, 6A, 00, 8B, 0D, 80, 34, 77, 00, B2, 01, A1, BC, 04, 75, 00, E8, 87, 71, F6, FF, A1, AC, 18, 80, 00, 8B, 00, E8, 6B, A7, CA, FF, A1, AC, 18, 80, 00, 8B, 00, 8B, 50, 74, 8D, 14, 52, 89, 50, 74, A1, AC, 18, 80, 00, 8B, 00, E8, 03, A8, CA, FF, E8, 3E, 71, C1, FF, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.9 MB (4,115,456 bytes)

Scan Henzo.exe - Powered by Reason Core Security