osf64.exe

PassMark Software OSForensics

PassMark Software Pty Ltd

Publisher:
PassMark® Software  (signed by PassMark Software Pty Ltd)

Product:
PassMark Software OSForensics

Description:
OSForensics

Version:
3.0.1000.0

MD5:
04c1229294a9df6cbca1284965c9cc7f

SHA-1:
d48acabd0bd4b3a3f5f3151170890544ae97d20d

SHA-256:
173a7d834487c54adc2f0a8d211eddc6b2eb47dafbb33c06144f8095eb089347

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 10:07:36 PM UTC  (today)

File size:
23 MB (24,149,176 bytes)

Product version:
3.0.1000.0

Copyright:
Copyright © 2010-2014

Trademarks:
PassMark®

Original file name:
osf.exe

File type:
Executable application (Win64 EXE)

Language:
English (Australia)

Common path:
C:\Program Files\osforensics\osf64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/28/2012 2:00:00 AM

Valid to:
9/29/2015 1:59:59 AM

Subject:
CN=PassMark Software Pty Ltd, O=PassMark Software Pty Ltd, STREET="Suite 202, Level 2,", STREET=35 Buckingham Street, STREET=Surry Hills, L=Sydney, S=NSW, PostalCode=2010, C=AU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F7FFBB08767ECB4632603215492777DF

File PE Metadata
Compilation timestamp:
7/11/2014 11:38:05 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x675FE0

Entry point:
48, 83, EC, 28, E8, FB, B1, 01, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 18, 48, 89, 74, 24, 20, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 81, EC, A0, 00, 00, 00, 48, 8B, 05, 4B, 6B, 49, 00, 48, 33, C4, 48, 89, 84, 24, 98, 00, 00, 00, 48, 8B, FA, 48, 63, F1, 89, 74, 24, 4C, 33, DB, 8B, C3, 48, 85, D2, 0F, 95, C0, 85, C0, 75, 17, E8, 77, CB, FE, FF, 89, 18, E8, 50, CB, FE, FF, C7, 00, 16, 00, 00, 00, E9, 34, 03, 00, 00, 33, D2, 44, 8D, 42, 38, 48, 8B, CF, E8, 53, 9C, FE, FF, 83, FE, FE...
 
[+]

Entropy:
6.3332

Code size:
7 MB (7,373,824 bytes)

Scan osf64.exe - Powered by Reason Core Security