xtrapva.dll

Wiselogic Co., Ltd.

Publisher:
Wiselogic Co., Ltd.

Description:
Online Game Security Solution

Version:
1, 0, 0, 1

MD5:
1c0681ef0c321b2048f04307a5170ca4

SHA-1:
ad43a2b90ef2c007581e9cfd5441ec08892e3f00

SHA-256:
9575d1eb0ad7e69ac3a4f21152bbe7433b6496344e2d9afc89e679208876709d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 5:08:54 PM UTC  (today)

File size:
4.2 MB (4,453,352 bytes)

Copyright:
Wiselogic Co., Ltd.

Trademarks:
X-TRAP

File type:
Dynamic link library (Win32 DLL)

Language:
Korean (Korea)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\xtrapva.dll

File PE Metadata
Compilation timestamp:
7/20/2016 7:41:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:9DG8Vfe9fnJu+kwy3t3CWQONYHxZa54gCIFYee4+Bpx8VCLzC9YNxVAcT/:9bwnD7y3t3FRSRi/eB4+nxo0C9YNE0

Entry address:
0xEC6044

Entry point:
68, 96, 3B, 2F, 1B, 89, 04, 24, 52, 57, BF, 2E, E9, BF, 63, 81, C7, 91, 96, E6, 1E, C1, EF, 03, C1, E7, 03, 81, E7, EC, 27, E5, 2F, 81, C7, 58, D8, 5B, FD, 89, FA, 8B, 3C, 24, 81, C4, 04, 00, 00, 00, 89, 54, 24, 04, 5A, 57, 50, B8, 01, 00, 00, 00, 89, 44, 24, 04, 8B, 04, 24, 51, 54, 59, 81, C1, 04, 00, 00, 00, 81, C1, 04, 00, 00, 00, 87, 0C, 24, 5C, 55, 89, 0C, 24, 89, E1, 81, C1, 04, 00, 00, 00, 55, BD, 04, 00, 00, 00, 29, E9, 5D, 87, 0C, 24, 5C, 89, 2C, 24, C7, 04, 24, 00, 00, 40, 40, E8, 00, 00, 00, 00...
 
[+]

Entropy:
7.9701  (probably packed)

Code size:
7.5 MB (7,815,168 bytes)

The file xtrapva.dll has been seen being distributed by the following 10 URLs.

http://dl.cf.vtc.vn/xtrap/.../XTrapVa.dll

http://45.64.187.22/xtrap/.../XTrapVa.dll

http://cfpatch.z8game.com/xtrap/.../XTrapVa.dll

http://cfpatch.z8game.com/xtrap/.../XTrapVa.dll

http://es.cfpatch.z8games.com/xtrap/.../XTrapVa.dll

http://cfpatch.z8game.com/xtrap/.../XTrapVa.dll

http://dl.cf.vtc.vn/xtrap/.../XTrapVa.dll

http://update.cfire.ru/xtrap/.../XTrapVa.dll

Scan xtrapva.dll - Powered by Reason Core Security