iiscryptocli.exe

IIS Crypto Command Line

Nartac Software Inc.

Publisher:
Nartac Software Inc.  (signed and verified)

Product:
IIS Crypto Command Line

Version:
1.6.7.0

MD5:
3b2c89a356dc56844919e25d7cf19fb1

SHA-1:
ee08d673cbbd4420d2ee9ab681c887132de2671a

SHA-256:
14d484fe55005d4ad53ca10e2bdde04121386a3f173d154b37a4a6cb1235221e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/15/2025 5:39:33 AM UTC  (today)

File size:
63.2 KB (64,720 bytes)

Product version:
1.6.7.0

Copyright:
Copyright © 2011-2014 Nartac Software Inc.

Original file name:
IISCrypto.Cli.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\iiscryptocli.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
4/22/2013 10:22:07 PM

Valid to:
4/23/2015 10:41:50 PM

Subject:
E=contact@nartac.com, CN=Nartac Software Inc., O=Nartac Software Inc., L=Vancouver, S=British Columbia, C=CA, Description=hgY7dJz6ec6yx19Y

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0988

File PE Metadata
Compilation timestamp:
11/17/2014 6:41:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:WO8iaqCnHBcodl1KJiJLJ2J/JXTSChTc+DVqXkvUCowl/s2T5mbCn1NOMVV5k4yZ:baqcBcod6Y5U1EIthrVAjuY

Entry address:
0xE26A

Entry point:
FF, 25, 78, E2, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4C, E2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, 95, 6A, 54, 00, 00, 00, 00, 02, 00, 00, 00, 7E, 00, 00, 00, 9C, E2, 00, 00, 9C, C4, 00, 00, 52, 53, 44, 53, E6, E7, FB, 55, E7, 14, 74, 4B, B7, 62, 49, A9, 51, 6A, ED, D6, 01, 00, 00, 00, 43, 3A, 5C, 44, 61, 74, 61, 5C, 53, 75, 62, 76, 65, 72, 73, 69, 6F, 6E, 5C, 47, 69, 64, 64, 65, 6E, 73, 5C, 54, 72, 75, 6E, 6B, 5C, 50, 72, 6F, 6A, 65, 63, 74, 73, 5C, 4E, 61, 72, 74, 61, 63, 5C, 49, 49, 53, 43, 72...
 
[+]

Entropy:
5.6644

Code size:
49 KB (50,176 bytes)

The file iiscryptocli.exe has been seen being distributed by the following URL.

Scan iiscryptocli.exe - Powered by Reason Core Security