EC2HibernateAgent.exe

  • File Path: C:\Program Files\Amazon\Hibernate\EC2HibernateAgent.exe
  • Description:

Hashes

Type Hash
MD5 BAF2DC4F2419BFC0DEA2BC2609DA5F5B
SHA1 D8B1E277E419729FC177CF7F28D02339EFEC5766
SHA256 25C4F7BBC409CDEC1B144034C7E79F88AAE97C74E0ED72888F19817E47ACFBB5
SHA384 349C28BE361A913A1A7874D7661CEEC14DAD716BB873C7B323532C249EAAA4160A6395135FFAD3CD9889A13B97AE820E
SHA512 471A269E08D0025CBEDAA285038D3359D0EE412E2ACE1D6F993EC62C2A9AFB05CA11677561C8C96DF1F087C3D25C0CA8E5F3593707D1C0FD4552E7EFEF69EC91
SSDEEP 384:B8jcgHZevkMSZsHLPK6jTu7LwvZevkAZsHLsu1PnhY:e7kPKgOUfLhY
IMP F34D5F2D4577ED6D9CEEC516C1F5A744
PESHA1 767D97913034939751E76BAF6EF3C110CC2B276F
PE256 D238CAB89DAC82FFFAF96DBD0B63982F227793AA70D93608EFE89D78DABC2C28

Runtime Data

Usage (stderr):


Unhandled Exception: System.ArgumentException: Invalid parameter name: --help
   at EC2HibernateAgent.Main(String[] args)

Child Processes:

EC2HibernateAgent.exe WerFault.exe

Open Handles:

Path Type
(RW-) C:\Users\user File
...\Cor_SxSPublic_IPCBlock Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000004.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro Section
\BaseNamedObjects\Cor_Private_IPCBlock_v4_4880 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section

Loaded Modules:

Path
C:\Program Files\Amazon\Hibernate\EC2HibernateAgent.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\5543cca0df435801e2303ff46a482ed5\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\f29b1120627489754c4b8dd317bbe950\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bb0ca52db926eaec4a94a8b656f61a94\System.Management.Automation.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_64\System\6885802f40fd803e49150d8a2b43a09b\System.ni.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\bcrypt.dll
C:\Windows\System32\bcryptPrimitives.dll
C:\Windows\System32\combase.dll
C:\Windows\SYSTEM32\CRYPTBASE.dll
C:\Windows\System32\CRYPTSP.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\IMM32.DLL
C:\Windows\System32\kernel.appcore.dll
C:\Windows\System32\KERNEL32.dll
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\MSCOREE.DLL
C:\Windows\System32\msvcp_win.dll
C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\ole32.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\system32\rsaenh.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\SHLWAPI.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\SYSTEM32\VERSION.dll
C:\Windows\System32\win32u.dll

Signature

  • Status: Signature verified.
  • Serial: 0B6484A34E527CC2BC614568F961D353
  • Thumbprint: 5E025F525F7CCDB57B9E0AD40C7022184536A52D
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=”Amazon Web Services, Inc.”, O=”Amazon Web Services, Inc.”, L=Seattle, S=Washington, C=US, PostalCode=98109, STREET=410 Terry Ave N, SERIALNUMBER=4152954, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

File Metadata

  • Original Filename: EC2HibernateAgent.exe
  • Product Name:
  • Company Name:
  • File Version: 0.0.0.0
  • Product Version: 0.0.0.0
  • Language: Language Neutral
  • Legal Copyright:
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/64
  • VirusTotal Link: https://www.virustotal.com/gui/file/25c4f7bbc409cdec1b144034c7e79f88aae97c74e0ed72888f19817e47acfbb5/detection/

MIT License. Copyright (c) 2020-2021 Strontic.