winja.exe

PHROZEN SOFTWARE (PHROZEN SAS)

Publisher:
Phrozen SAS  (signed by PHROZEN SOFTWARE (PHROZEN SAS))

Description:
Winja - Catch presense of Malware in your system

Version:
1.0.0.0

MD5:
6624588b36106c1ae809825da5f99658

SHA-1:
a0bcfb11b5557953c808bbf8c790f6e444917841

SHA-256:
2dd35539a03daba9bc2c268ab93e1f38702184180a3d74811889517ba1bbaa55

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 7:54:14 AM UTC  (today)

File size:
8.8 MB (9,208,368 bytes)

Product version:
1.0.0.0

Copyright:
(c) 2016

Trademarks:
Phrozen Software™

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\phrozenwinja\winja.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/18/2015 5:30:00 AM

Valid to:
11/18/2017 5:29:59 AM

Subject:
CN=PHROZEN SOFTWARE (PHROZEN SAS), O=PHROZEN SOFTWARE (PHROZEN SAS), STREET=12B rue de la Muette, L=Maisons Laffitte, S=Yvelines, PostalCode=78600, C=FR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DC9768E6091113E137EAF897D0436221

File PE Metadata
Compilation timestamp:
5/28/2016 9:00:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:lM/v+GdiUoyly1JUPjhMv4WTiCt2CdgMhcPt2X9dQLkmpkgAy4Q6Spm:y+GxqULTBmFhcPQAwmpehQ6Spm

Entry address:
0x499F90

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, BC, 86, 88, 00, E8, 60, 48, B7, FF, 8B, 1D, AC, BC, 8B, 00, 33, C0, 55, 68, 6B, A2, 89, 00, 64, FF, 30, 64, 89, 20, A1, 2C, B5, 8B, 00, C6, 00, 01, A1, A0, B3, 8B, 00, 8B, 00, 33, C9, BA, 88, A2, 89, 00, E8, 21, 6F, EA, FF, 8B, F0, 8D, 55, EC, 8B, C6, E8, CD, DF, E4, FF, 8B, 45, EC, E8, D9, C3, E5, FF, 8D, 55, E0, B8, 01, 00, 00, 00, E8, C8, CB, B6, FF, 8B, 45, E0, 8D, 55, E4, E8, 01, 97, B8, FF, 8B, 45, E4, 8D, 55, E8, E8, BE, 92...
 
[+]

Entropy:
6.7692

Developed / compiled with:
Microsoft Visual C++

Code size:
4.6 MB (4,819,968 bytes)

Scan winja.exe - Powered by Reason Core Security