wlsDll.dll

Nanjing Zhixiao Information Technology Co.,Ltd

Publisher:

Version:
2.0.0.3

MD5:
e3a8bd9eec169c8c0c22d94c52432561

SHA-1:
35919ec0f12f8832ecb9fcf1844f8ea4007fa968

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 2:01:03 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
DLOADER.Trojan
9.0.1.09

File size:
699.8 KB (716,640 bytes)

Product version:
2.0.0.3

Original file name:
wlsDll.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\wlsdll.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/14/2013 8:00:00 AM

Valid to:
11/15/2014 7:59:59 AM

Subject:
CN="Nanjing Zhixiao Information Technology Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Nanjing Zhixiao Information Technology Co.,Ltd", L=Nanjing, S=Jiangsu, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
20E65F5D29B5822410504B1AC183CA3D

File PE Metadata
Compilation timestamp:
12/11/2013 6:16:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:5vFI4zrg6DNVl9SlT1ygoiHkKQMG1SbsHdB9Xjcvgv7dP37fkkc5NrM:FZNn9dMGooHFbTfkkc5NrM

Entry address:
0x68B3A

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 31, DE, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 50, 1B, 0A, 10, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 50, 1B, 0A, 10, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF...
 
[+]

Entropy:
6.2757

Code size:
523 KB (535,552 bytes)

Scan wlsDll.dll - Powered by Reason Core Security