xtrapva.dll

Wiselogic Co., Ltd.

Publisher:
Wiselogic Co., Ltd.  (signed and verified)

Description:
Online Game Security Solution

Version:
1, 0, 0, 1

MD5:
4068d72a6d1674685ffdfaac8468e703

SHA-1:
4163282e7c3ae2e0ddbca2fd6f152cdb1f841caa

SHA-256:
749243c523d7017cfb113c28776ca964c79b0c41ac3cf7d771e72ebd5a588317

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/26/2024 11:10:01 PM UTC  (a few moments ago)

File size:
1.3 MB (1,412,376 bytes)

Copyright:
Wiselogic Co., Ltd.

Trademarks:
X-TRAP

File type:
Dynamic link library (Win32 DLL)

Language:
Korean (Korea)

Common path:
C:\Program Files\z8games\crossfire\xtrap\xtrapva.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/23/2012 2:00:00 AM

Valid to:
11/23/2013 1:59:59 AM

Subject:
CN="Wiselogic Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wiselogic Co., Ltd.", L=Gangnam gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
13BEF1CE41B008BD8BD048FEEE0268AA

File PE Metadata
Compilation timestamp:
8/19/2013 1:04:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:qGcYxjj6wL4Tq/KMbFvAwsDnl+GHHY6fWQdWcOLNq6ZDPyLrUa:YY4NTqiOvA7HJ9IcOB6M

Entry address:
0x3E9044

Entry point:
68, 00, 00, 00, 00, 68, 01, 00, 00, 00, 68, 00, 00, 40, 40, E8, 00, 00, 00, 00, 81, 2C, 24, 58, 90, 7E, 40, 81, 04, 24, 00, 80, 7E, 40, E9, 95, 1F, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8974

Packer / compiler:
PKLITE32, 0x1.1

Code size:
1.1 MB (1,183,744 bytes)

The file xtrapva.dll has been seen being distributed by the following 3 URLs.

http://cfsapatch.z8games.com/xtrap/.../XTrapVa.dll

Scan xtrapva.dll - Powered by Reason Core Security