nplog.dll

超霸传奇微端

Mianyang FiveThreeNineThree Technology Co.,Ltd

Publisher:
绵阳亿趣科技  (signed by Mianyang FiveThreeNineThree Technology Co.,Ltd)

Product:
超霸传奇微端

Description:
超霸传奇登录器

Version:
2.0.0.0

MD5:
c6a2011e3bfe32f26c207ca6bc387788

SHA-1:
bd15e2df5b067c1873acb35f8fa9eb06e658a51c

SHA-256:
bcb878a6f55fea09f9a346d2b607c71fdcebcd0f23d4238818630586b637e504

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/30/2024 9:38:13 PM UTC  (today)

File size:
598.7 KB (613,024 bytes)

Product version:
2.0.0.0

Copyright:
绵阳亿趣科技

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nplog.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
7/3/2015 5:01:33 PM

Valid to:
12/30/2016 12:00:00 AM

Subject:
CN="Mianyang FiveThreeNineThree Technology Co.,Ltd", O="Mianyang FiveThreeNineThree Technology Co.,Ltd", L=Mianyang, S=Sichuan, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
646AB2B9C0F4AB8C19863F1D0B0DA38E

File PE Metadata
Compilation timestamp:
6/3/2016 11:16:26 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
12288:8pkMAVQi6t2RtOif0LAdrpXsXA3NlLkd8xwNAytUe8GvQViTJhDgVIFU:8pkPVlwQJ948ayGvQATTkya

Entry address:
0x4B724

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, C2, 80, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, A8, A0, 08, 10, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, 6E, BF, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, 5E, BF, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01...
 
[+]

Entropy:
6.6114

Code size:
424 KB (434,176 bytes)

Scan nplog.dll - Powered by Reason Core Security