islamic.azad.university(semnan.branch).exe

DevalVR 3D Plugin

Phoscode SL

Publisher:
www.devalvr.com  (signed by Phoscode SL)

Product:
DevalVR 3D Plugin

Description:
DevalVR 3D Plugin 0,9,1,4

Version:
0.9.1.4

MD5:
31848683904a7726d9c3479d65859bc0

SHA-1:
eb973236d1a2fb6f84d7a5e57f1142ecd98cf9b4

SHA-256:
06340e4e8969437e6c0414258f15bd04a0a846fe3ee89ccfe0f513ad0cd0f9dc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:20:29 PM UTC  (today)

File size:
412.6 MB (432,693,672 bytes)

Product version:
0.9.1.4

Copyright:
Copyright © Phoscode S.L.

Original file name:
npdevalvr.dll

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\autoplay\docs\islamic.azad.university(semnan.branch).exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/16/2013 4:00:00 PM

Valid to:
1/17/2018 3:59:59 PM

Subject:
CN=Phoscode SL, O=Phoscode SL, STREET=Calle Diego de Velazquez 1 - 3 K, L=Villamediana de Iregua, S=La Rioja, PostalCode=26142, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B25A4B2751600A88986461D3A9C2DC58

File PE Metadata
Compilation timestamp:
2/8/2014 7:29:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6291456:PHqa1Phs/KkjcDC0Lcy51U7gvJjfm+gf+Io6jwfvVVpMxCo1rB3ITOOxsoMETElI:PB1PQjnYI72dVj6Mb2vYTDMETKI

Entry address:
0xCEA19

Entry point:
E8, 4B, 91, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, A0, DB, 54, 00, 75, 02, F3, C3, E9, 88, 00, 00, 00, 51, C7, 01, 08, 0C, 51, 00, E8, AE, 96, 00, 00, 59, C3, 55, 8B, EC, 8D, 41, 09, 50, 8B, 45, 08, 83, C0, 09, 50, E8, 0D, 96, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 55, 8B, EC, 56, 8B, F1, E8, C9, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 0E, 8E, F4, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, FF, 15, 64, 91, 50, 00, 6A, 01, A3, BC, 46, 55, 00, E8, CB, 96, 00, 00, FF, 75, 08, E8, 5F, 95, 00...
 
[+]

Entropy:
7.9940  (probably packed)

Code size:
1 MB (1,078,784 bytes)

Scan islamic.azad.university(semnan.branch).exe - Powered by Reason Core Security