win2pdfs.dll

Dane Prairie Systems, LLC

Publisher:
Dane Prairie Systems, LLC  (signed and verified)

MD5:
87338eb943166f865071aa7287755446

SHA-1:
3ad20fdabfcebb1b430f56b80120a53e15f99462

SHA-256:
994aba3818bfcbe42958ded9d9206f28a684e143fda201377bcff70af76a56a9

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/27/2024 3:54:53 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.Wpbrutebot-2
0.98/21411

File size:
149.6 KB (153,240 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\windows\syswow64\win2pdfs.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/21/2013 7:00:00 PM

Valid to:
1/22/2016 6:59:59 PM

Subject:
CN="Dane Prairie Systems, LLC", O="Dane Prairie Systems, LLC", STREET=5524 Concord Ave, L=Minneapolis, S=MN, PostalCode=55424-1565, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00852F8783B57D1A3A72DB08F74DC568BF

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:QsAi+mYzcQsgW1fqaeYm4Vb1DHEyjJO/vxp2ikzjFtuWVUzZRPA3My7CXwHcnObf:T3+mjLSNMVV43DkPFtuWVUzzwHcnObFd

Entry address:
0x1ED3C

Entry point:
55, 8B, EC, 83, C4, C4, B8, 74, EC, 41, 00, E8, 5C, 77, FE, FF, E8, 87, 56, FE, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5689

Developed / compiled with:
Microsoft Visual C++

Code size:
119.5 KB (122,368 bytes)

Scan win2pdfs.dll - Powered by Reason Core Security