hookwinsockv5.dll

IEInspector HookWinsock

Anqing Inspector Software Ltd.

Publisher:
IEInspector Software  (signed by Anqing Inspector Software Ltd.)

Product:
IEInspector HookWinsock

Description:
HTTPAnalyzer Winsock Hook

Version:
5.2.1.224

MD5:
3b8f65e82146755e0992ddd102c9e459

SHA-1:
f084e4a9019efb1237ca3d71b13ad635e2fe3451

SHA-256:
d8c87de42935db712a1c46390572d87f6ae4444eb1d0b03b916fa0f68c95ad09

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 12:08:33 PM UTC  (today)

File size:
617.5 KB (632,320 bytes)

Product version:
V5

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ieinspector\httpanalyzerfullv5\hookwinsockv5.dll

Digital Signature
Authority:
WoSign, Inc.

Valid from:
12/9/2009 7:00:00 AM

Valid to:
12/10/2011 6:59:59 AM

Subject:
CN=Anqing Inspector Software Ltd., OU=WoSign Class 3 Code Signing, O=Anqing Inspector Software Ltd., L=Anqing, S=Anhui, C=CN

Issuer:
CN=WoSign Code Signing Authority, O="WoSign, Inc.", C=US

Serial number:
00E67CF8A0C52BB27D55391A687F119D8A

File PE Metadata
Compilation timestamp:
1/22/2010 7:34:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:uwV1XrudCfXs2ZmvoEOmj+X0jzsLJAQbhdNSL0he7mzqMXGgJoq2DTGew:l1udmT08mj+X0jzsLJZXNSL0he70+DTY

Entry address:
0x862AC

Entry point:
55, 8B, EC, 83, C4, C4, B8, 84, 46, 48, 00, E8, 18, 0C, F8, FF, E8, 9F, E1, FF, FF, 84, C0, 74, 0D, A1, 2C, F3, 48, 00, C7, 00, 01, 00, 00, 00, EB, 3F, E8, 0D, AD, FA, FF, C6, 40, 08, 00, E8, 04, AD, FA, FF, C6, 40, 09, 01, E8, FB, AC, FA, FF, 83, C0, 04, BA, 20, 63, 48, 00, E8, C2, E9, F7, FF, 33, D2, B8, 3C, 63, 48, 00, E8, DA, 97, FE, FF, E8, 31, 86, FA, FF, E8, 5C, DD, FF, FF, E8, 2F, 86, FA, FF, E8, 5A, E8, F7, FF, 00, 00, FF, FF, FF, FF, 12, 00, 00, 00, 48, 74, 74, 70, 41, 6E, 61, 6C, 79, 7A, 65, 72...
 
[+]

Entropy:
6.7338

Developed / compiled with:
Microsoft Visual C++

Code size:
531.5 KB (544,256 bytes)

Scan hookwinsockv5.dll - Powered by Reason Core Security