By using Saferwall you consent to our Terms of Service and Privacy Policy and allow us to share your submission with the security community. Learn more

Summary

Analyse score

2/ 13

2 antivirus venders flagged
this file as malicious

Last scanned

First submission

File type

dll

dll

Basic properties

CRC32

0x8c5f3e1b

MD5

39f103c5363456840a9f323c2fd7f17d

Magic

PE32+ executable (native) x86-64, for MS Windows

SHA1

45759316692f5431f0ab3c57bd1736463a063cb1

SHA256

b8dfce081fddf7c9a4aef07a5aaf400b16c7b27befc5b290ee8185c4653f7c78

SHA512

01c90ecad7eb67f7637a46b08303f2104223bfde5e6bca6ae80cab4868363866825028fe9afae180a8a70d69b60c1f1a3b2ee0abfaadcb6ff7369224b6e2f868

SSDeep

768:ZkCOeX2Yg5KY6VgQqd12zBdZp0IEz1hEn:nzn60BaIjn

Size

44.15KB

TLSH

a8135a87d71918c5e9bbc67da9e98727fe70f805833183eb1215c2125f22fe2a538342

Packer
  • PE+(64): compiler: Microsoft Visual C/C++(2008 SP1)[-]
  • PE+(64): linker: Microsoft Linker(9.0)[Driver64,signed]
TrID
  • 56.5% (.EXE) Win64 Executable (generic) (10523/12/4)
  • 11.0% (.ICL) Windows Icons Library (generic) (2059/9)
  • 10.9% (.EXE) OS/2 Executable (generic) (2029/13)
  • 10.7% (.EXE) Generic Win/DOS Executable (2002/3)
  • 10.7% (.EXE) DOS Executable Generic (2000/1)
Tags

ExifTool File Metadata

CharacterSet

Windows, Latin1

CodeSize

21.00KB

CompanyName

wj32

EntryPoint

0x9064

ExifToolVersionNumber

12.96

FileDescription

KProcessHacker

FileFlags

(none)

FileFlagsMask

0x003f

FileOs

Win32

FileSize

45 kB

FileSubtype

7

FileType

Win64 EXE

FileTypeExtension

exe

FileVersion

3.0

FileVersionNumber

3.0.0.0

ImageFileCharacteristics

Executable, Large address aware

ImageVersion

6.1

InitializedDataSize

5.50KB

LanguageCode

English (U.S.)

LegalCopyright

Licensed under the GNU GPL, v3.

LinkerVersion

9.0

MachineType

AMD AMD64

MimeType

application/octet-stream

ObjectFileType

Driver

OriginalFileName

kprocesshacker.sys

OsVersion

6.1

PeType

PE32+

ProductName

KProcessHacker

ProductVersion

3.0

ProductVersionNumber

3.0.0.0

Subsystem

Native

SubsystemVersion

6.1

UninitializedDataSize

0

Submissions

Published Name Source Country
b8dfce081fddf7c9a4aef07a5aaf400b16c7b27befc5b290ee8185c4653f7c78 web
N/A