networkwizardloader.exe

XpressConnect

Cloudpath Networks, Inc.

Publisher:
Cloudpath Networks, Inc.  (signed and verified)

Product:
XpressConnect

Version:
3.05.0058

MD5:
5d1911c1f67574cf0fb3bfb68a0b229c

SHA-1:
7b9ac43222d832f52d0e9893ef168f67b5e78411

SHA-256:
c00b1609a76b9ec81abe42e82ee9daa5b17bf8cdc028ea7d1f94a15f6123b84f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:03:48 PM UTC  (today)

File size:
425.5 KB (435,736 bytes)

Product version:
3.05.0058

Copyright:
Copyright 2010, Cloudpath Networks Inc.

Original file name:
xc_loader_exe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\networkwizardloader.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
2/19/2009 7:00:00 PM

Valid to:
5/16/2011 7:59:59 PM

Subject:
CN="Cloudpath Networks, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="Cloudpath Networks, Inc.", L=Broomfield, S=Colorado, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
623884085348A58EC66358FCC4838B85

File PE Metadata
Compilation timestamp:
10/21/2010 11:49:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:O2fO+1/0/m3rEzunoEISyDPjDFS3yC+Eh4o:liu7ounoznM3yNEKo

Entry address:
0x2EF4

Entry point:
68, D8, 3C, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 80, B1, 38, 24, 5C, 1C, 46, 44, B5, BC, A5, C0, 2B, 3E, 45, A8, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 41, 00, 06, 50, 83, 02, 78, 63, 5F, 6C, 6F, 61, 64, 65, 72, 5F, 65, 78, 65, 00, F6, 00, 00, 00, 00, 00, FF, CC, 31, 00, 20, E3, B6, 0C, 6C, 7A, 1B, D9, 4B, 9D, 12, CA, 78, 95, 2F, 3A, 20, 8E, 86, C9, 0E, AB, FF, 3F, 47, 89, EC, 0C, DE, C1, 4A, 17, 34, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
6.3378

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
160 KB (163,840 bytes)

Scan networkwizardloader.exe - Powered by Reason Core Security