wxzkuzrlxp.exe

Borland Database Explorer

Borland Software Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from awo-omamma.com.
Publisher:
Borland Software Corporation

Product:
Borland Database Explorer

Version:
6.0.6.163

MD5:
2ce8770c32e9c896f8f6a4911dbfbcee

SHA-1:
3a38a5eca4ce9bde328133e8485db530da6ad4b0

SHA-256:
78218691299863ef9d923714e8bc6e9ba6d336237a12296dcb31446441403010

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 6:03:50 AM UTC  (today)

File size:
1 MB (1,089,024 bytes)

Product version:
6.0

Copyright:
Copyright (C) 1995-2001 Borland Software Corporation

Original file name:
dbexplor.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\wxzkuzrlxp.exe

File PE Metadata
Compilation timestamp:
9/30/1991 8:57:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:syFdEXQAWqe7HqB793HjuQPYPk22dZcYioEM3PEd:5YwAhPYx2dDnx3PEd

Entry address:
0xB45E8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 28, 43, 4B, 00, E8, 10, 27, F5, FF, A1, 00, F2, 4B, 00, 8B, 00, E8, E8, E7, F9, FF, 8B, 0D, 88, F3, 4B, 00, A1, 00, F2, 4B, 00, 8B, 00, 8B, 15, 14, 3C, 4B, 00, E8, E8, E7, F9, FF, A1, 00, F2, 4B, 00, 8B, 00, E8, 5C, E8, F9, FF, E8, 2F, FF, F4, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
718 KB (735,232 bytes)

The file wxzkuzrlxp.exe has been seen being distributed by the following URL.

Scan wxzkuzrlxp.exe - Powered by Reason Core Security