dftest.exe

  • File Path: C:\Program Files\Wireshark\dftest.exe

Hashes

Type Hash
MD5 049B4FA2F5ABEED3D65D516CE3BDC6FE
SHA1 8358448EA1087F34956C38373683C2D47A8B2F15
SHA256 07F28305D10810B766683C5ACFC80DF985C3A9B51724B41D9027C9D684D0A943
SHA384 3A80109BDC76BA972471886B514223965383AF8F4ADC2B8E028D37E6D914BCC733486D12A46F7610E03C8960E2A0F50D
SHA512 107AEFCE1FD22324DCEA546E9E52B22123F1BCF910ECE6EFACB9DA7F74779F3A9486A5A1F120C474AA7F7EB68BCF68EFB2D67C17AB7896FDA904010DEAD42C99
SSDEEP 384:HaXxhII0V5zkEYU6aWIcAM+VvsqgxGfZ48JN77hhwt:yPIdorWMivsgb3hmt
IMP 0470AF7E1F79D9BC16920D3A59A88BE0
PESHA1 BE7FC33D164D098E74B3E14C4A731203D5228D37
PE256 3A85F034D0C662A84A7CD84BC3AA7F276FA3CBFBBCA695AC39C1B0F0EFDE1724

Runtime Data

Usage (stdout):

Filter: "C:\temp\strontic-xcyclopedia\notepad.exe"

Usage (stderr):

dftest: "--help" is neither a field nor a protocol name.

Loaded Modules:

Path
C:\Program Files\Wireshark\dftest.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 02CCD99F7D556C13CE8710C69D09B31A
  • Thumbprint: E8EF7325044D018B0C0DCD8CBA4190B155857F3B
  • Issuer: CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
  • Subject: CN=”Wireshark Foundation, Inc.”, O=”Wireshark Foundation, Inc.”, STREET=711 4th street, L=Davis, S=CA, PostalCode=95616, C=US

File Metadata

  • Original Filename:
  • Product Name:
  • Company Name:
  • File Version:
  • Product Version:
  • Language:
  • Legal Copyright:
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/07f28305d10810b766683c5acfc80df985c3a9b51724b41d9027c9d684d0a943/detection/

File Similarity (ssdeep match)

File Score
C:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe 27
C:\program files (x86)\Common Files\Apple\Apple Application Support\plutil.exe 27
C:\program files (x86)\Common Files\Apple\Apple Application Support\VersionCheckMe.exe 29
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\distnoted.exe 27
C:\program files\Common Files\Apple\Apple Application Support\VersionCheckMe.exe 29
C:\Program Files\Wireshark\mmdbresolve.exe 35

MIT License. Copyright (c) 2020-2021 Strontic.