| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 1970-Jan-01 00:00:00 |
| Detected languages |
English - United States
|
| CompanyName | Westbridge Services Inc. |
| OriginalFilename | EnterpriseCenter.exe |
| FileDescription | Enterprise Center - System component for configuration and updates |
| FileVersion | 5.1.5322.214 |
| InternalName | EnterpriseCenter.exe |
| LegalCopyright | Copyright (c) 2015-2025 Westbridge Services Inc. |
| ProductVersion | 5.1.5322.214 |
| ProductName | Enterprise Center |
| Suspicious | PEiD Signature: | HQR data file |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA256 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .xdata
Unusual section name found: .symtab |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Enterprise Center
Issuer: Enterprise Center |
| Malicious | VirusTotal score: 9/70 (Scanned on 2026-06-06 10:54:45) |
Bkav:
W32.Malware.A8A7194E
CrowdStrike: win/malicious_confidence_60% (D) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Malwarebytes: Trojan.Loader Microsoft: Trojan:Win32/Wacatac.B!ml Rising: Trojan.Generic!8.C3 (CLOUD) Tencent: Trojan.Win64.Rozena.he Trapmine: suspicious.low.ml.score |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0x8b |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 9 |
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| PointerToSymbolTable | 0x1d8200 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 3.0 |
| SizeOfCode | 0xbc800 |
| SizeOfInitializedData | 0x4f200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000067B60 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.1 |
| ImageVersion | 1.0 |
| SubsystemVersion | 6.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x27c000 |
| SizeOfHeaders | 0x600 |
| Checksum | 0x1f61e5 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x200000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| kernel32.dll |
WriteFile
WriteConsoleW WerSetFlags WerGetFlags WaitForMultipleObjects WaitForSingleObject VirtualQuery VirtualFree VirtualAlloc TlsAlloc SwitchToThread SuspendThread SetWaitableTimer SetProcessPriorityBoost SetEvent SetErrorMode SetConsoleCtrlHandler RtlVirtualUnwind RtlLookupFunctionEntry ResumeThread RaiseFailFastException PostQueuedCompletionStatus LoadLibraryW LoadLibraryExW SetThreadContext GetThreadContext GetSystemInfo GetSystemDirectoryA GetStdHandle GetQueuedCompletionStatusEx GetProcessAffinityMask GetProcAddress GetErrorMode GetEnvironmentStringsW GetCurrentThreadId GetConsoleMode FreeEnvironmentStringsW ExitProcess DuplicateHandle CreateWaitableTimerExW CreateThread CreateIoCompletionPort CreateFileA CreateEventA CloseHandle AddVectoredExceptionHandler AddVectoredContinueHandler |
|---|
| Enterprise Center |
| Enterprise Center - System component for configuration and updates |
| Westbridge Services Inc. |
| Version 5.1.5322.214 |
| Copyright (c) 2015-2025 Westbridge Services Inc. |
| Item 5916: skipped. |
| Item 2685: skipped. |
| Service stopped. |
| Microphone access granted. |
| Disable |
| Item 1481: pending. |
| Disk free: 128 GB |
| Select All |
| Item 4906: skipped. |
| Camera access denied |
| The specified path is invalid. |
| Access is denied. |
| This action cannot be undone. |
| An unexpected error has occurred. |
| The process cannot access the file because it is being used by another process. |
| The system cannot find the file specified. |
| Unable to write to the specified location. |
| Item 1454: ready. |
| Item 3506: ready. |
| Item 1403: ready. |
| Preparing... |
| Item 3068: ready. |
| Printer: HP LaserJet ready |
| Loading... |
| In Progress |
| Working... |
| Item 6390: ready. |
| Item 7269: ready. |
| Item 6275: ready. |
| Item 2218: ready. |
| Item 7286: updated. |
| Download complete. |
| Item 1787: updated. |
| Item 3229: updated. |
| Item 9701: updated. |
| Packets received: 8,390 |
| Network unavailable. |
| SSL handshake completed. |
| License valid until December 31, 2026. |
| Sign in to continue. |
| Microsoft account connected. |
| Work or school account added |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.1.5322.214 |
| ProductVersion | 5.1.5163.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS
VOS_DOS_WINDOWS16
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS_OS232
VOS_OS232_PM32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Westbridge Services Inc. |
| OriginalFilename | EnterpriseCenter.exe |
| FileDescription | Enterprise Center - System component for configuration and updates |
| FileVersion (#2) | 5.1.5322.214 |
| InternalName | EnterpriseCenter.exe |
| LegalCopyright | Copyright (c) 2015-2025 Westbridge Services Inc. |
| ProductVersion (#2) | 5.1.5322.214 |
| ProductName | Enterprise Center |
| Resource LangID | English - United States |
|---|
No comments yet.