MWUser.exe

Rainbow Security Solution

LEMA I&T CO., LTD

Publisher:
LEMA I&T CO., LTD  (signed and verified)

Product:
Rainbow Security Solution

Description:
Rainbow Role Impersonator

Version:
1, 0, 11, 705

MD5:
652ecad379d43f76786062b9372aedf2

SHA-1:
495301f738c89637ae6db5fc8cc7267c395f00fc

SHA-256:
0375ae1278ff04f262a74d58d27b1e1ac2644ffb42d9fd0d312cc38d47d5f027

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 4:48:27 AM UTC  (today)

File size:
60.3 KB (61,736 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) LEMA I&T Co., Ltd

Trademarks:
Rainbow Security Solution

Original file name:
MWUser.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\mwuser.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/15/2011 9:00:00 AM

Valid to:
9/15/2012 8:59:59 AM

Subject:
CN="LEMA I&T CO., LTD", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LEMA I&T CO., LTD", L=SUWON, S=KYEONGGI-DO, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00C23C2122D73F8F4F6EFDC1FEEB43C1

File PE Metadata
Compilation timestamp:
10/21/2011 4:45:48 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:qS/E52SpdaVa19mwVks3hbUTXmHgVy/HRMoe24BUvRyu5UF49MLFml:HOIa3lkU1oXGgVOHR7erUX5UFkMol

Entry address:
0x1F70

Entry point:
48, 83, EC, 28, E8, C7, 23, 00, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, DD, B1, 00, 00, FF, 15, 7F, 71, 00, 00, 48, 8B, 05, C8, B2, 00, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, F5, 6B, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24...
 
[+]

Entropy:
6.2322

Code size:
31.5 KB (32,256 bytes)

Scan MWUser.exe - Powered by Reason Core Security