Wow64.lmd

Wow64 Actions Plugin

Ulrich Peters

Publisher:
MindQuake Serviços de Informática Ltda.  (signed by Ulrich Peters)

Product:
Wow64 Actions Plugin

Version:
1, 0, 5, 0

MD5:
9cef4049fe735220b1b0227062188f9d

SHA-1:
e0a52b1a94fcd4734cf0b560b5b48933bd6f8073

SHA-256:
74712faf77e0fcfa5a97d1e430f005fe62710a6804c69d3674a50356bbd3aa95

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/24/2024 3:06:41 PM UTC  (today)

Scan engine
Detection
Engine version

F-Secure
Win32.Sality.4
5.14.151

File size:
103.8 KB (106,256 bytes)

Product version:
2, 0, 0, 0

Copyright:
Copyright © 2010-2013 MindQuake Serviços de Informática Ltda.

Original file name:
Wow64.lmd

Language:
English (United States)

Common path:
C:\windows\temp\ir_ext_temp_14\autoplay\plugins\wow64\wow64.lmd

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/21/2013 1:00:00 AM

Valid to:
1/22/2015 12:59:59 AM

Subject:
CN=Ulrich Peters, O=Ulrich Peters, STREET="Rua Angelo Bertini, 111", STREET=Apt. 43, L=São Paulo, S=São Paulo, PostalCode=04195-090, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BE0BFBEC6739C7AF45672524203F144B

File PE Metadata
Compilation timestamp:
8/16/2013 1:30:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:jYIBBn6dE2LCo1bLubqqJt3oGlqFvryKA:8wBn6d3bLaoGlQlA

Entry address:
0x128F0

Entry point:
B8, 5C, F0, 04, 10, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 36, 46, 79, 02, A1, 65, 11, BE, 49, 38, 9D, 23, E2, A8, 40, DF, 12, A6, 57, 5C, 88, 73, 73, 25, 63, 13, 37, 34, 78, 6F, 93, 1B, 1E, D0, AC, FC, 32, C7, C3, 2E, CE, 48, 9C, 0A, A1, E5, E0, 56, 65, 9B, 19, 92, AF, 6A, C3, 4E, DA, 40, C0, 0D, 97, 60, 37, F5, 22, 5A, 7E, 42, C1, D8, 94, 6C, 04, 8A, 9B, 90, C6, A8, 91, 2D, 6B, 3B, 6F, C1, D3, 01, 9C, FF, 93, AE, ED, 1E, 6F...
 
[+]

Packer / compiler:
PECompact v2

Code size:
141 KB (144,384 bytes)

Scan Wow64.lmd - Powered by Reason Core Security