xtrapva.dll

Wiselogic Co., Ltd.

Publisher:
Wiselogic Co., Ltd.  (signed and verified)

Description:
Online Game Security Solution

Version:
1, 0, 0, 1

MD5:
cbd6e7c6e40b0c6b287e50a934f426c8

SHA-1:
5ac29dbc65c8a1619074898e7196f739e14402ee

SHA-256:
b1fc9b278214ec3cf3d09b09d1ebe4de3723f02a80bcb7976808a5203629a2c4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 9:56:24 PM UTC  (today)

File size:
1.4 MB (1,449,240 bytes)

Copyright:
Wiselogic Co., Ltd.

Trademarks:
X-TRAP

File type:
Dynamic link library (Win32 DLL)

Language:
Korean (Korea)

Common path:
C:\Program Files\crossfire ph\xtrap\xtrapva.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/23/2012 8:00:00 AM

Valid to:
11/23/2013 7:59:59 AM

Subject:
CN="Wiselogic Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wiselogic Co., Ltd.", L=Gangnam gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
13BEF1CE41B008BD8BD048FEEE0268AA

File PE Metadata
Compilation timestamp:
9/5/2013 11:08:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:YDr7rLP7gKGlVZeNa3B65BXo1yn+k1oVlhyp+0GPau6b1+f:orfLnSAaxCsyn+kiVbe+Eu6bw

Entry address:
0x3F4044

Entry point:
68, 00, 00, 00, 00, 68, 01, 00, 00, 00, 68, 00, 00, 40, 40, E8, 00, 00, 00, 00, 81, 2C, 24, 58, 40, 7F, 40, 81, 04, 24, 00, 30, 7F, 40, E9, 95, 1F, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8966

Packer / compiler:
PKLITE32, 0x1.1

Code size:
1.1 MB (1,196,032 bytes)

The file xtrapva.dll has been seen being distributed by the following 3 URLs.

Scan xtrapva.dll - Powered by Reason Core Security