winsecret.exe

CV. TweakNow

Publisher:
CV. TweakNow  (signed and verified)

MD5:
cf35aaa2213d75101f5dcd4c7d677d5c

SHA-1:
b329929fb2ae256a0f37ab05edb817ec12cae1c5

SHA-256:
4366b3213d339bd8aec7240ce2b9469d2401ef089522d6fa4123e0e61e295c90

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:48:17 AM UTC  (today)

File size:
11.1 MB (11,675,448 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\xenocode\sandbox\1.0.0.0\2010.12.24t03.24\virtual\modified\@programfiles@\tweaknow winsecret 2011\winsecret.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/20/2010 7:30:00 PM

Valid to:
1/21/2011 7:29:59 PM

Subject:
CN=CV. TweakNow, O=CV. TweakNow, STREET=JL. Antariksa No. 12, L=Bandung, S=Jawa Barat, PostalCode=40175, C=ID

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00C8AB6D0E6BF1D94DC7BCB8913E10BBA4

File PE Metadata
Compilation timestamp:
12/16/2010 6:29:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
196608:CEN1r0OUz7Bbsl8yTCXxuDSWzhVGFxsARlnehKUzaoL5c5j+opLmupBEO51zGjFI:CyuH7BbtymXxgSWmFxsARRehKUzaoL5M

Entry address:
0x213C

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, AC, D0, B5, 00, A1, 9F, D0, B5, 00, C1, E0, 02, A3, A3, D0, B5, 00, 52, 6A, 00, E8, E7, 93, 75, 00, 8B, D0, E8, 86, 93, 6F, 00, 5A, E8, A8, 92, 6F, 00, E8, D3, 94, 6F, 00, 6A, 00, E8, BC, B1, 6F, 00, 59, 68, 48, D0, B5, 00, 6A, 00, E8, C1, 93, 75, 00, A3, A7, D0, B5, 00, 6A, 00, E9, 3B, 5D, 70, 00, E9, EE, B1, 6F, 00, 33, C0, A0, 91, D0, B5, 00, C3, A1, A7, D0, B5, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, EC, 00, 00, 00, 0B, C9...
 
[+]

Code size:
7.4 MB (7,716,864 bytes)

Scan winsecret.exe - Powered by Reason Core Security