nitrosd.dll

BinaryThing.com Pty Ltd

Publisher:
ARTS PDF  (signed by BinaryThing.com Pty Ltd)

Version:
1.0.0.0

MD5:
e897f8d84d402ef95afa09756c8b4b07

SHA-1:
acc15869435ab31feceec6a679997329b8f3148f

SHA-256:
b656988d7ea505a31f68205ec41167866bab56e63d8193827eaa6910b06a3c6d

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/11/2017 6:17:30 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Worm.Sytro!6.BB
23.00.65.15415

File size:
118.4 KB (121,272 bytes)

Product version:
1.0.0.0

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\windows\syswow64\nitrosd.dll

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
11/24/2006 8:00:00 AM

Valid to:
11/24/2008 7:59:59 AM

Subject:
CN=BinaryThing.com Pty Ltd, OU=ARTS PDF, O=BinaryThing.com Pty Ltd, L=Melbourne, S=Vic, C=AU

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
531FE18DC102C5A4A49846E46F781439

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:EzzI0Z4a1iT7chrzILs9TpAgHRxL3el6VPWCaS0dVWHujdyE:0EMETupFVPBkT

Entry address:
0x18F20

Entry point:
55, 8B, EC, 83, C4, C4, B8, 70, 8E, 41, 00, E8, 54, D4, FE, FF, E8, DB, B0, FE, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5397

Developed / compiled with:
Microsoft Visual C++

Code size:
96 KB (98,304 bytes)

Scan nitrosd.dll - Powered by Reason Core Security