Gridinsoft Logo
File Icon

The OfiProR.exe File Analysis

Technical Analysis

File Name OfiProR.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-25 08:01:11 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
64,757,352
File Size (bytes)
2025-03-25
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6fdc05affcf8c94298c4e808c55f3976
SHA1
2846b8179876c643368eb93cd7583a599262395b
SHA256
002707b5e1789e527a0954fbdbe4b59e5f829fc36130f01238dfc87d45d1ded2
SHA512
89d12a8034649e70bf0ccedc1d806029caeecad27bc176ef7eb255bfe5e06fd1fade2ad1eb942f8418bdcb47a4789b549a19b224639f0253dbd192ca0dafa8da
ImpHash
da6d597ec71490514349fadb5cca9a9e

PE Analysis

Basic Information

Icon
Hash: 1f6bb8cdfdabbe12a73aae0c6b3efc13
Fuzzy: 54326c0083d2675012acb44abc729767
dHash: d0a082a6a2b2aab2
Image Base 0x00400000
Entry Point 0x02b55cb0
Compilation Time 2025-03-11 13:14:15
Checksum 0x03dca903 (Actual: 0x03dca903)
OS Version 5.1
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature OK
Imports 26 libraries
Exports 2 functions
Resources 1524 Resources
Sections 11 Sections

Version Information

FileDescription Cliente Windows de OfiPro Runtime
FileVersion 2025.3.14.4
LegalCopyright 2000-2025, OfiPro Soluciones
LegalTrademarks OfiPro, GesPro, ContaPro
ProductName OfiPro
ProductVersion 1.0.0.0
Translation 0x0c0a 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 41,523,868 bytes 41,524,224 bytes 5.75 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 32403A1F0E2ABCAA7878F2E6A7401731
.data 0x0279b000 3,303,976 bytes 3,304,448 bytes 5.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 457766A41A8FBE9D06F2C19703F74DBC
.bss 0x02ac2000 108,692 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x02add000 34,652 bytes 34,816 bytes 4.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8B89CD1CC6B5C1E883F093AC1697D57F
.didata 0x02ae6000 14,946 bytes 15,360 bytes 3.89 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 40281B5F4E6D6E1CC69CB4BD0C30A9C6
.edata 0x02aea000 112 bytes 512 bytes 1.42 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EA17FD31D694E7959918A8017C0D3707
.tls 0x02aeb000 1,056 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x02aec000 109 bytes 512 bytes 1.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DAC329C0942CA1DA5F76EBABC99FB049
.reloc 0x02aed000 1,767,452 bytes 1,767,936 bytes 6.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ B1804FB02F2BA88ED52FEDEE4504A19C
.pdata 0x02c9d000 1,533,540 bytes 1,533,952 bytes 6.98 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FB2CA2F1BE548DA3C9F0567DEA330966
.rsrc 0x02e14000 16,561,664 bytes 16,561,664 bytes 7.19 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AC80345B7561D1F951A056195B7E6248
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 1524 (16,442,741 bytes)
Resource Type Count Total Size Percentage
RCDATA 1 1,786 bytes
0%
XML 4 30,457 bytes
0.2%
RT_CURSOR 31 9,548 bytes
0.1%
RT_BITMAP 455 603,788 bytes
3.7%
RT_ICON 9 182,974 bytes
1.1%
RT_DIALOG 2 164 bytes
0%
RT_STRING 219 244,350 bytes
1.5%
RT_RCDATA 769 15,366,755 bytes
93.5%
RT_GROUP_CURSOR 31 620 bytes
0%
RT_GROUP_ICON 1 132 bytes
0%
RT_VERSION 1 672 bytes
0%
RT_MANIFEST 1 1,495 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware