Attention: please enable javascript in order to properly view and use this malware analysis service.

Indicators

Not all malicious and suspicious indicators are displayed. Get your own cloud service or the full version to view all details.

  • Suspicious Indicators 1

  • Unusual Characteristics
    • Imports suspicious APIs
      details
      TerminateProcess
      UnhandledExceptionFilter
      IsDebuggerPresent
      GetTickCount
      Sleep
      source
      Static Parser
      relevance
      1/10
  • Informative 7

  • Anti-Reverse Engineering
  • Environment Awareness
  • External Systems
  • General
    • Contains PDB pathways
      details
      "C:\build\sec_scc\_source\util\bin\ObfuscationUtil.pdb"
      source
      String
      relevance
      1/10
    • The input sample is signed with a certificate
      details
      The input sample is signed with a certificate issued by "CN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, ST=Western Cape, C=ZA" (SHA1: 6C:07:45:3F:FD:DA:08:B8:37:07:C0:9B:82:FB:3D:15:F3:53:36:B1; see report for more information)
      The input sample is signed with a certificate issued by "CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US" (SHA1: 65:43:99:29:B6:79:73:EB:19:2D:6F:F2:43:E6:76:7A:DF:08:34:E4; see report for more information)
      The input sample is signed with a certificate issued by "OU=Class 3 Public Primary Certification Authority, O="VeriSign
      Inc.", C=US" (SHA1: 32:F3:08:82:62:2B:87:CF:88:56:C6:3D:B8:73:DF:08:53:B4:DD:27; see report for more information)
      The input sample is signed with a certificate issued by "CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa c10, OU=VeriSign Trust Network, O="VeriSign
      Inc.", C=US" (SHA1: E0:6B:03:8B:CE:C8:F9:E0:12:A3:AD:DD:BC:EE:B8:68:0F:B0:B7:FD; see report for more information)
      The input sample is signed with a certificate issued by "CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="c 2006 VeriSign
      Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign
      Inc.", C=US" (SHA1: 49:58:47:A9:31:87:CF:B8:C7:1F:84:0C:B7:B4:14:97:AD:95:C6:4F; see report for more information)
      source
      Certificate Data
      relevance
      10/10
  • Network Related
    • Found potential URL in binary/memory
      details
      Pattern match: "http://ocsp.thawte.com0"
      Pattern match: "http://crl.thawte.com/ThawteTimestampingCA.crl0"
      Pattern match: "http://ts-ocsp.ws.symantec.com07"
      Pattern match: "http://ts-aia.ws.symantec.com/tss-ca-g2.cer0"
      Pattern match: "http://ts-crl.ws.symantec.com/tss-ca-g2.crl0"
      Pattern match: "http://crl.verisign.com/pca3.crl0"
      Pattern match: "https://www.verisign.com/cps0"
      Pattern match: "http://logo.verisign.com/vslogo.gif04"
      Pattern match: "http://ocsp.verisign.com0"
      Pattern match: "https://www.verisign.com/rpa"
      Pattern match: "http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D"
      Pattern match: "https://www.verisign.com/rpa0"
      Pattern match: "http://csc3-2010-aia.verisign.com/CSC3-2010.cer0"
      Pattern match: "https://www.verisign.com/cps0*"
      Pattern match: "http://crl.verisign.com/pca3-g5.crl04"
      source
      String
      relevance
      10/10
  • Unusual Characteristics

File Details

All Details:

ObfuscationUtil.exe

Filename
ObfuscationUtil.exe
Size
74KiB (76280 bytes)
Type
peexe executable
Description
PE32 executable (console) Intel 80386, for MS Windows
Architecture
WINDOWS
SHA256
c32506bc05235b861802598098c7bf3658baf6ee4c01f8be37c8ce8838d19c95Copy SHA256 to clipboard
Compiler/Packer
Visual C++ 2005 Release -> Microsoft

Resources

Language
ENGLISH
Icon
Sample Icon

Visualization

Input File (PortEx)
PE Visualization

Version Info

LegalCopyright
Copyright 2000-2013 Sophos Limited. All rights reserved.
InternalName
ObfuscationUtil.exe
FileVersion
5.2.1.79
CompanyName
Sophos Limited
LegalTrademarks
Sophos and Sophos Anti-Virus are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
ProductName
Sophos Endpoint Management
ProductVersion
5.2.1.79
FileDescription
Sophos Obfuscation Utility
OriginalFilename
ObfuscationUtil.exe
Translation
0x0809 0x04b0

File Sections

File Imports

CryptAcquireContextA
CryptGenRandom
CryptReleaseContext
DecodePointer
EncodePointer
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetSystemTimeAsFileTime
GetTickCount
HeapSetInformation
InterlockedCompareExchange
InterlockedExchange
IsDebuggerPresent
lstrlenA
lstrlenW
MultiByteToWideChar
QueryPerformanceCounter
SetUnhandledExceptionFilter
Sleep
TerminateProcess
UnhandledExceptionFilter
WideCharToMultiByte
No API names/ordinals defined for this module import
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z
?_BADOFF@std@@3_JB
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
?_Orphan_all@_Container_base0@std@@QAEXXZ
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ
?flags@ios_base@std@@QBEHXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
?good@ios_base@std@@QBE_NXZ
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD0@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
?uncaught_exception@std@@YA_NXZ
?width@ios_base@std@@QAE_J_J@Z
?width@ios_base@std@@QBE_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z
??0exception@std@@QAE@ABQBD@Z
??0exception@std@@QAE@ABQBDH@Z
??0exception@std@@QAE@ABV01@@Z
??0exception@std@@QAE@XZ
??1exception@std@@UAE@XZ
??2@YAPAXI@Z
??3@YAXPAX@Z
??_V@YAXPAX@Z
?_type_info_dtor_internal_method@type_info@@QAEXXZ
?terminate@@YAXXZ
?what@exception@std@@UBEPBDXZ
__CxxFrameHandler3
__dllonexit
__getmainargs
__initenv
__set_app_type
__setusermatherr
_amsg_exit
_cexit
_commode
_configthreadlocale
_controlfp_s
_crt_debugger_hook
_CxxThrowException
_except_handler4_common
_exit
_fmode
_initterm
_initterm_e
_invoke_watson
_lock
_onexit
_purecall
_recalloc
_stricmp
_unlock
_XcptFilter
calloc
exit
free
memcpy
memmove
memset
strlen
wcslen

File Certificates

Download Certificate File (7.5KiB)
Owner Issuer Validity Hashes (MD5, SHA1)
CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US CN=Thawte Timestamping CA, OU=Thawte Certification, O=Thawte, L=Durbanville, ST=Western Cape, C=ZA
Serial: 7e93ebfb7cc64e59ea4b9a77d406fc3b
12/21/2012 01:00:00
12/31/2020 00:59:59
7B:A3:69:EE:9A:BD:81:E0:FC:76:74:E9:70:9E:15:1D
6C:07:45:3F:FD:DA:08:B8:37:07:C0:9B:82:FB:3D:15:F3:53:36:B1
CN=Symantec Time Stamping Services Signer - G4, O=Symantec Corporation, C=US CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US
Serial: ecff438c8febf356e04d86a981b1a50
10/18/2012 02:00:00
12/30/2020 00:59:59
08:32:B6:5C:C3:E3:A4:9B:C3:81:BA:95:E1:B5:87:37
65:43:99:29:B6:79:73:EB:19:2D:6F:F2:43:E6:76:7A:DF:08:34:E4
CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="c 2006 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
Serial: 250ce8e030612e9f2b89f7054d7cf8fd
11/08/2006 01:00:00
11/08/2021 00:59:59
F9:1F:FE:E6:A3:6B:99:88:41:D4:67:DD:E5:F8:97:7A
32:F3:08:82:62:2B:87:CF:88:56:C6:3D:B8:73:DF:08:53:B4:DD:27
CN=Sophos Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sophos Limited, L=Abingdon, ST=Oxfordshire, C=GB CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa c10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial: 3224e125da6703112040ab66621435f
12/03/2010 01:00:00
12/03/2013 00:59:59
0C:1E:AF:D2:E0:76:45:BF:D5:5B:7B:F4:41:A0:38:B3
E0:6B:03:8B:CE:C8:F9:E0:12:A3:AD:DD:BC:EE:B8:68:0F:B0:B7:FD
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa c10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US CN=VeriSign Class 3 Public Primary Certification Authority - G5, OU="c 2006 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Serial: 5200e5aa2556fc1a86ed96c9d44b33c7
02/08/2010 01:00:00
02/08/2020 00:59:59
4D:F6:E0:FC:40:0C:AE:9C:05:2F:AE:98:C6:6D:37:9F
49:58:47:A9:31:87:CF:B8:C7:1F:84:0C:B7:B4:14:97:AD:95:C6:4F

Screenshots

Loading content, please wait...

Hybrid Analysis

Tip: Click an analysed process below to view more details.

Analysed 1 process in total.

Network Analysis

DNS Requests

No relevant DNS requests were made.

Contacted Hosts

No relevant hosts were contacted.

HTTP Traffic

No relevant HTTP requests were made.

Extracted Strings

All Details:
!This program cannot be run in DOS mode.$
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
#http://crl.verisign.com/pca3-g5.crl04
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
#http://logo.verisign.com/vslogo.gif04
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
%VeriSign Class 3 Code Signing 2010 CA
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
%VeriSign Class 3 Code Signing 2010 CA0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
'Symantec Time Stamping Services CA - G2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
'Symantec Time Stamping Services CA - G20
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+Symantec Time Stamping Services Signer - G40
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate <string> -w Sophos Limited 2004-2011
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate <string>String to obfuscate
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate myusername
Ansi based on Process Commandline (<Input Sample>)
-?Display this help
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
-wTreat string as wstring
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.2.1.79
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
.?AV?$_Iosb@H@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVbad_alloc@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVCAtlException@ATL@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVCObscurity@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVexception@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVInsufficientMemory@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVInternalInconsistency@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVIObscurity@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVios_base@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVNoInputData@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVObfuscation@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVObscurityException@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVPRNGInitialisation@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVPRNGUninitialised@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVRandomSeedGeneration@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVruntime_error@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVSecurityException@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVtype_info@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVUnproperInputData@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVWin32GetCryptographicContext@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.Class 3 Public Primary Certification Authority0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.http://crl.thawte.com/ThawteTimestampingCA.crl0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.rsrc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.text
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
/http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
/http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0$0,080X0`0h0p0x0|0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0$0<0@0X0h0l0p0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0+0:0@0Z0b0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
010>0K0_0h0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
061108000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1$181@1H1P1X1`1h1p1|1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(1-131;1A1G1T1Z1c1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(181<1L1P1T1X1`1x1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1+1<1I1S1]1g1n1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
100208000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
101203000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
121018000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
121221000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
130521165945Z0#
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
131202235959Z0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
162I2:3N3
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2 2%2,222D2L2R2^2i2~2v3|3
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2(2,2<2@2D2H2P2h2x2|2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2+2=2M2h2x2~2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
200207235959Z0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
201229235959Z0b1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
201230235959Z0^1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
211107235959Z0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
24282T2X2x2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
262C2_2o2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2Terms of use at https://www.verisign.com/rpa (c)101.0,
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
3-4:4E4Q4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
304l4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
4&414=4B4R4W4]4c4y4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
4(404H4P4X4h4p4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
4f5s5&656
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5 5/5J5W5
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5,545X5l5|5
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
54686<6@6D6H6L6P6
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5<6V6h6f7u7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5Digital ID Class 3 - Microsoft Software Validation v21
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5q6&7<7w7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6$6@6H6`6l6
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6%6F7U768E8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6+646F6U6z6
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
668E8f9u9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6H7M7_7}7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
7$707P7\7|7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
7+888I8Z8d8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
788<8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8 8(848T8\8d8l8x8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8H8f8x8$9-999B9N9Z9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8P9T9X9|9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9':E:R:v:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9,949@9h9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9:#:J:Z:j:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9@:D:H:p:t:x:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9a9F:X:x:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9C9K9V9\9b9h9n9t9z9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
: ;$;(;,;l;p;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:data=
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
:flags=
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
:H;h=n=c>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:OpenSSLErr=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:OpenSSLError=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
; ;(;0;8;D;d;l;t;|;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<,<<<@<T<X<h<l<t<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<8<@<H<P<\<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel> </requestedPrivileges> </security> </trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<VeriSign Class 3 Public Primary Certification Authority - G50
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=(=8=<=L=P=T=\=t=x=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=.=8=B=K=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=4=<=D=H=L=T=h=p=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
> >(>D>L>d>l>t>x>|>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
>0>@>D>H>L>P>X>p>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?"?(?.?4?:?@?F?L?R?X?^?d?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?$?,?8?d?l?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?4?8?P?T?l?|?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABQBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABQBDH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABV01@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1exception@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??2@YAPAXI@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??3@YAXPAX@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??_V@YAXPAX@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_BADOFF@std@@3_JB
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Orphan_all@_Container_base0@std@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_type_info_dtor_internal_method@type_info@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Xlength_error@std@@YAXPBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Xout_of_range@std@@YAXPBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?flags@ios_base@std@@QBEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?good@ios_base@std@@QBE_NXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD0@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?terminate@@YAXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?uncaught_exception@std@@YA_NXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?what@exception@std@@UBEPBDXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?width@ios_base@std@@QAE_J_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?width@ios_base@std@@QBE_JXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
@.data
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
@.reloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
\RPC Control\console-0x00000B34-lpc-handle
Unicode based on Runtime Data (ObfuscationUtil.exe )
\Sessions\1\Windows\ApiPort
Unicode based on Runtime Data (ObfuscationUtil.exe )
__CxxFrameHandler3
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__dllonexit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__getmainargs
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__initenv
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__set_app_type
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__setusermatherr
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_amsg_exit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_cexit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_commode
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_configthreadlocale
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_controlfp_s
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_crt_debugger_hook
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_CxxThrowException
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_except_handler4_common
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_exit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_fmode
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_initterm
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_initterm_e
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_invoke_watson
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_lock
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_onexit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_purecall
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_recalloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_stricmp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_unlock
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_XcptFilter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
`.rdata
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/vector<T> too long
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Abingdon1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ADVAPI32.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
AppID
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
as-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel> </requestedPrivileges> </security> </trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
ation Utility
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
bad allocation
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Base64Decode returned false
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Base64Encode returned false
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
C:\build\sec_scc\_source\util\bin\ObfuscationUtil.pdb
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
calloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Cipher.cpp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CLSID
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
CompanyName
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Component Categories
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Copyright 2000-2013 Sophos Limited. All rights reserved.
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Creating Win32 cryptographic context failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CryptAcquireContextA
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CryptGenRandom
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CryptReleaseContext
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CWDIllegalInDLLSearch
Unicode based on Runtime Data (ObfuscationUtil.exe )
DecodePointer
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Delete
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
Durbanville1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Dynamic memory allocation failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
EncodePointer
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Error :
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
FDGASSkwpodkfgfspwoegre;[addq[pad.col
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
FileDescription
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
FileType
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
FileVersion
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
ForceRemove
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentProcess
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentProcessId
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentThreadId
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetLastError
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetSystemTimeAsFileTime
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetTickCount
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Hardware
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
HeapSetInformation
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ht 2000-2013 Sophos Limited. All rights reserved.
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
http://crl.verisign.com/pca3.crl0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.thawte.com0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ts-ocsp.ws.symantec.com07
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/cps0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/cps0*
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/rpa0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
image/gif0!0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InitPRNG.cpp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Interface
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InterlockedCompareExchange
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InterlockedExchange
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Internal system inconsistency.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InternalName
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
invalid string position
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
IsDebuggerPresent
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
KERNEL32.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
LegalCopyright
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
LegalTrademarks
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
LIBEAY32.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
lstrlenA
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
lstrlenW
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MemBuff.cpp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
memcpy
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
memmove
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
memset
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
mited
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
MSVCP100.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MSVCR100.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MultiByteToWideChar
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
No input data.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
NoRemove
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
Obfuscated string :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obfuscation failed :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obfuscation Tool Usage :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ObfuscationUtil.exe
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Failed to obscure data:sts=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Failed to reveal data:sts=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Invalid algorithm ident=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Invalid parameters (null pointer)
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Not enough data to perform decryption
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
onUtil.exe
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
OpenSSL PRNG is not initialised.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
opyright
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
OriginalFilename
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Oxfordshire1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
PRNG initialisation failed, probably mo enough random seed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ProductName
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
ProductVersion
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
QueryPerformanceCounter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Random seed generation failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Revealed name length is zero
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
s are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
SECURITY
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
SetUnhandledExceptionFilter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sleep
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Software
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
Sophos and Sophos Anti-Virus are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Endpoint Management
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Limited
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Limited0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Limited1>0<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Obfuscation Utility
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
string too long
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
StringFileInfo
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
strlen
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Symantec Corporation100.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Symantec Corporation1402
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
SYSTEM
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
TerminateProcess
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ternalName
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
Thawte Certification1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Thawte Timestamping CA0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
TimeStamp-2048-10
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
TimeStamp-2048-20
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Translation
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
TransparentEnabled
Unicode based on Runtime Data (ObfuscationUtil.exe )
TypeLib
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
UnhandledExceptionFilter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Unproper input data.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Unrecognized parameter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VarFileInfo
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
vector<T> too long
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
VeriSign Trust Network1:08
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSign Trust Network1;09
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSign, Inc.1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSign, Inc.1705
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSignMPKI-2-80
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VS_VERSION_INFO
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
wcslen
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Western Cape1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
WideCharToMultiByte
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
!This program cannot be run in DOS mode.$
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
#http://crl.verisign.com/pca3-g5.crl04
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
#http://logo.verisign.com/vslogo.gif04
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.2.1.79
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
.?AV?$_Iosb@H@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVbad_alloc@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVCAtlException@ATL@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVCObscurity@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVexception@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVInsufficientMemory@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVInternalInconsistency@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVIObscurity@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVios_base@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVNoInputData@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVObfuscation@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVObscurityException@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVPRNGInitialisation@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVPRNGUninitialised@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVRandomSeedGeneration@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVruntime_error@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVSecurityException@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVtype_info@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVUnproperInputData@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVWin32GetCryptographicContext@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.http://crl.thawte.com/ThawteTimestampingCA.crl0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
/http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
/http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0+0:0@0Z0b0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2(2,2<2@2D2H2P2h2x2|2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2Terms of use at https://www.verisign.com/rpa (c)101.0,
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8 8(848T8\8d8l8x8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9':E:R:v:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9:#:J:Z:j:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9@:D:H:p:t:x:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9a9F:X:x:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
: ;$;(;,;l;p;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:OpenSSLError=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<8<@<H<P<\<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel> </requestedPrivileges> </security> </trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=(=8=<=L=P=T=\=t=x=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?"?(?.?4?:?@?F?L?R?X?^?d?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABQBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABQBDH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABV01@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1exception@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??2@YAPAXI@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??3@YAXPAX@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??_V@YAXPAX@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_BADOFF@std@@3_JB
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Orphan_all@_Container_base0@std@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_type_info_dtor_internal_method@type_info@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Xlength_error@std@@YAXPBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Xout_of_range@std@@YAXPBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?flags@ios_base@std@@QBEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?good@ios_base@std@@QBE_NXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD0@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?terminate@@YAXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?uncaught_exception@std@@YA_NXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?what@exception@std@@UBEPBDXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?width@ios_base@std@@QAE_J_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?width@ios_base@std@@QBE_JXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
@.data
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
@.reloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
\RPC Control\console-0x00000B34-lpc-handle
Unicode based on Runtime Data (ObfuscationUtil.exe )
\Sessions\1\Windows\ApiPort
Unicode based on Runtime Data (ObfuscationUtil.exe )
__getmainargs
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_configthreadlocale
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
as-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel> </requestedPrivileges> </security> </trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
C:\build\sec_scc\_source\util\bin\ObfuscationUtil.pdb
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Copyright 2000-2013 Sophos Limited. All rights reserved.
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Creating Win32 cryptographic context failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Dynamic memory allocation failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Error :
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
FDGASSkwpodkfgfspwoegre;[addq[pad.col
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentProcess
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentProcessId
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetLastError
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ht 2000-2013 Sophos Limited. All rights reserved.
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
http://crl.verisign.com/pca3.crl0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.thawte.com0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ts-ocsp.ws.symantec.com07
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/cps0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/cps0*
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/rpa0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
image/gif0!0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obfuscation failed :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ObfuscationUtil.exe
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Failed to obscure data:sts=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Failed to reveal data:sts=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Invalid parameters (null pointer)
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
onUtil.exe
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
PRNG initialisation failed, probably mo enough random seed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Random seed generation failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
s are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
Sophos and Sophos Anti-Virus are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
VS_VERSION_INFO
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate myusername
Ansi based on Process Commandline (<Input Sample>)
.2.1.79
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
\RPC Control\console-0x00000B34-lpc-handle
Unicode based on Runtime Data (ObfuscationUtil.exe )
\Sessions\1\Windows\ApiPort
Unicode based on Runtime Data (ObfuscationUtil.exe )
AppID
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
as-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel> </requestedPrivileges> </security> </trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
ation Utility
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
CLSID
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
CWDIllegalInDLLSearch
Unicode based on Runtime Data (ObfuscationUtil.exe )
Delete
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
FileType
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
Hardware
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
ht 2000-2013 Sophos Limited. All rights reserved.
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
mited
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
NoRemove
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
onUtil.exe
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
opyright
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
s are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
SECURITY
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
Software
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
SYSTEM
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
ternalName
Unicode based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DE2000.00000002.mdmp)
TransparentEnabled
Unicode based on Runtime Data (ObfuscationUtil.exe )
TypeLib
Ansi based on Memory/File Scan (ObfuscationUtil.exe , 00017151-00002696.00000000.17652.00DDD000.00000004.mdmp)
image/gif0!0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
061108000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
100208000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
101203000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
121018000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
121221000000Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
130521165945Z0#
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
131202235959Z0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
200207235959Z0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
201229235959Z0b1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
201230235959Z0^1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
211107235959Z0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate <string> -w Sophos Limited 2004-2011
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://crl.verisign.com/pca3.crl0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
!This program cannot be run in DOS mode.$
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
#http://crl.verisign.com/pca3-g5.crl04
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
#http://logo.verisign.com/vslogo.gif04
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
%VeriSign Class 3 Code Signing 2010 CA
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
%VeriSign Class 3 Code Signing 2010 CA0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
'Symantec Time Stamping Services CA - G2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
'Symantec Time Stamping Services CA - G20
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
+Symantec Time Stamping Services Signer - G40
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
--obfuscate <string>String to obfuscate
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
-?Display this help
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
-wTreat string as wstring
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$_Iosb@H@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVbad_alloc@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVCAtlException@ATL@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVCObscurity@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVexception@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVInsufficientMemory@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVInternalInconsistency@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVIObscurity@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVios_base@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVNoInputData@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVObfuscation@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVObscurityException@Obscurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVPRNGInitialisation@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVPRNGUninitialised@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVRandomSeedGeneration@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVruntime_error@std@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVSecurityException@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVtype_info@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVUnproperInputData@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.?AVWin32GetCryptographicContext@PhoenixSecurity@@
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.Class 3 Public Primary Certification Authority0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.http://crl.thawte.com/ThawteTimestampingCA.crl0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.rsrc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
.text
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
/http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
/http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0$0,080X0`0h0p0x0|0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0$0<0@0X0h0l0p0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
0+0:0@0Z0b0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
010>0K0_0h0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1$181@1H1P1X1`1h1p1|1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(1-131;1A1G1T1Z1c1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(181<1L1P1T1X1`1x1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
1+1<1I1S1]1g1n1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
162I2:3N3
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2 2%2,222D2L2R2^2i2~2v3|3
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2(2,2<2@2D2H2P2h2x2|2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2+2=2M2h2x2~2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
24282T2X2x2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
262C2_2o2
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
2Terms of use at https://www.verisign.com/rpa (c)101.0,
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
3-4:4E4Q4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
304l4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
4&414=4B4R4W4]4c4y4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
4(404H4P4X4h4p4
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
4f5s5&656
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5 5/5J5W5
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5,545X5l5|5
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
54686<6@6D6H6L6P6
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5<6V6h6f7u7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5Digital ID Class 3 - Microsoft Software Validation v21
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
5q6&7<7w7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6$6@6H6`6l6
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6%6F7U768E8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6+646F6U6z6
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
668E8f9u9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
6H7M7_7}7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
7$707P7\7|7
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
7+888I8Z8d8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
788<8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8 8(848T8\8d8l8x8
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8H8f8x8$9-999B9N9Z9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
8P9T9X9|9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9:#:J:Z:j:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9':E:R:v:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9,949@9h9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9@:D:H:p:t:x:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9a9F:X:x:
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
9C9K9V9\9b9h9n9t9z9
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
: ;$;(;,;l;p;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:data=
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
:flags=
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
:H;h=n=c>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:OpenSSLErr=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
:OpenSSLError=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
; ;(;0;8;D;d;l;t;|;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<,<<<@<T<X<h<l<t<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<8<@<H<P<\<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel> </requestedPrivileges> </security> </trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
<VeriSign Class 3 Public Primary Certification Authority - G50
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=(=8=<=L=P=T=\=t=x=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=.=8=B=K=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
=4=<=D=H=L=T=h=p=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
> >(>D>L>d>l>t>x>|>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
>0>@>D>H>L>P>X>p>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?"?(?.?4?:?@?F?L?R?X?^?d?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?$?,?8?d?l?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?4?8?P?T?l?|?
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABQBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABQBDH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@ABV01@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??0exception@std@@QAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??1exception@std@@UAE@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??2@YAPAXI@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??3@YAXPAX@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
??_V@YAXPAX@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_BADOFF@std@@3_JB
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Orphan_all@_Container_base0@std@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_type_info_dtor_internal_method@type_info@@QAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Xlength_error@std@@YAXPBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?_Xout_of_range@std@@YAXPBD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEDXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?flags@ios_base@std@@QBEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?good@ios_base@std@@QBE_NXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXH@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IBEPADXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD00@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEXPAD0@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?terminate@@YAXXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QBEPAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?uncaught_exception@std@@YA_NXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?what@exception@std@@UBEPBDXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?width@ios_base@std@@QAE_J_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?width@ios_base@std@@QBE_JXZ
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
@.data
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
@.reloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__CxxFrameHandler3
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__dllonexit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__getmainargs
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__initenv
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__set_app_type
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
__setusermatherr
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_amsg_exit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_cexit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_commode
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_configthreadlocale
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_controlfp_s
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_crt_debugger_hook
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_CxxThrowException
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_except_handler4_common
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_exit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_fmode
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_initterm
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_initterm_e
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_invoke_watson
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_lock
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_onexit
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_purecall
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_recalloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_stricmp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_unlock
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
_XcptFilter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
`.rdata
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/vector<T> too long
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Abingdon1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ADVAPI32.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
bad allocation
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Base64Decode returned false
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Base64Encode returned false
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
C:\build\sec_scc\_source\util\bin\ObfuscationUtil.pdb
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
calloc
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Cipher.cpp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CompanyName
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Component Categories
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Copyright 2000-2013 Sophos Limited. All rights reserved.
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Creating Win32 cryptographic context failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CryptAcquireContextA
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CryptGenRandom
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
CryptReleaseContext
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
DecodePointer
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Durbanville1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Dynamic memory allocation failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
EncodePointer
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Error :
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
FDGASSkwpodkfgfspwoegre;[addq[pad.col
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
FileDescription
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
FileVersion
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
ForceRemove
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentProcess
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentProcessId
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetCurrentThreadId
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetLastError
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetSystemTimeAsFileTime
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
GetTickCount
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
HeapSetInformation
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.thawte.com0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0;
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ocsp.verisign.com0>
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
http://ts-ocsp.ws.symantec.com07
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/cps0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/cps0*
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
https://www.verisign.com/rpa0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InitPRNG.cpp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Interface
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InterlockedCompareExchange
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InterlockedExchange
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Internal system inconsistency.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
InternalName
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
invalid string position
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
IsDebuggerPresent
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
KERNEL32.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
LegalCopyright
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
LegalTrademarks
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
LIBEAY32.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
lstrlenA
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
lstrlenW
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MemBuff.cpp
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
memcpy
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
memmove
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
memset
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MSVCP100.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MSVCR100.dll
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
MultiByteToWideChar
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
No input data.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obfuscated string :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obfuscation failed :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obfuscation Tool Usage :
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ObfuscationUtil.exe
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Failed to obscure data:sts=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Failed to reveal data:sts=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Invalid algorithm ident=
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Invalid parameters (null pointer)
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Obscure:Not enough data to perform decryption
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
OpenSSL PRNG is not initialised.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
OriginalFilename
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Oxfordshire1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
PRNG initialisation failed, probably mo enough random seed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
ProductName
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
ProductVersion
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
QueryPerformanceCounter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Random seed generation failed.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Revealed name length is zero
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
SetUnhandledExceptionFilter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sleep
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos and Sophos Anti-Virus are registered trademarks of Sophos Limited. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Endpoint Management
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Limited
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Limited0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Limited1>0<
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Sophos Obfuscation Utility
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
string too long
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
StringFileInfo
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
strlen
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Symantec Corporation100.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Symantec Corporation1402
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
TerminateProcess
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Thawte Certification1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Thawte Timestamping CA0
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
TimeStamp-2048-10
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
TimeStamp-2048-20
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Translation
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
UnhandledExceptionFilter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Unproper input data.
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Unrecognized parameter
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VarFileInfo
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
vector<T> too long
Ansi based on Hybrid Analysis (ObfuscationUtil.exe.bin)
VeriSign Trust Network1:08
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSign Trust Network1;09
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSign, Inc.1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSign, Inc.1705
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VeriSignMPKI-2-80
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
VS_VERSION_INFO
Unicode based on Memory/File Scan (ObfuscationUtil.exe.bin)
wcslen
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
Western Cape1
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)
WideCharToMultiByte
Ansi based on Memory/File Scan (ObfuscationUtil.exe.bin)

Extracted Files

No significant files were extracted.

Notifications

  • Runtime

  • Added comment to Virus Total report

Community