File Name | Forza-Mods-AIO.exe |
File Type |
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
|
Scanner Version | 1.0.158.174 |
Database Version | 2024-02-10 20:00:39 UTC |
Malware family: Agent
Hash Type | Value | Action |
---|---|---|
MD5 |
2f7f70031c7dabaed4b08373bde17ba6
|
|
SHA1 |
5748fdbb062b09e153fb9faa27a00b7ac6dc4e14
|
|
SHA256 |
02f2fe6810b2318e85b2da640b788488d7a4d69626bd781d5e128d221b4564a2
|
|
SHA512 |
d12f0bccc7389d90fac4e45d67b71ec7cfb21aeb83c62135c2e68d40aeac0b64521422e18acf72284715711104f4c3eb839398913bf172c7ec743b04f03ef601
|
Icon |
Hash: a50b0f1bb7b8a8b0815b814d1a53fcf6
Fuzzy: 9de21bfb86d694a60bb590b2fa07de78 dHash: 904cb394e4b64900 |
Image Base | 0x00400000 |
Entry Point | 0x00400000 |
Compilation Time | 2062-05-29 03:59:04 |
Checksum | 0x00000000 (Actual: 0x008f19f8) |
OS Version | 4.0 |
PEiD Signatures |
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
|
PDB Path | Forza-Mods-AIO.pdb |
Digital Signature | The PE file does not contain a certificate table. |
Imports | 0 |
Exports | 0 functions |
Resources | 4 Resources |
Sections | 2 Sections |
Translation | 0x0000 0x04b0 |
Comments | Modding tool for Forza Horizon 4 and 5 |
CompanyName | Forza Mods |
FileDescription | Forza-Mods-AIO |
FileVersion | 0.0.0.52 |
InternalName | Forza-Mods-AIO.exe |
LegalCopyright | Copyright © 2021 |
LegalTrademarks | |
OriginalFilename | Forza-Mods-AIO.exe |
ProductName | Forza-Mods-AIO |
ProductVersion | 0.0.0.52 |
Assembly Version | 0.0.0.52 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00002000 |
9,305,744 bytes | 9,306,112 bytes | 7.99 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
33AB2A0495E57364A7D24B74BBE20069 |
.rsrc |
0x008e2000 |
6,000 bytes | 6,144 bytes | 5.69 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B4EE15305282C7204B02B1EE7C10F1F9 |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 1 | 4,264 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_VERSION | 1 | 950 bytes | |
RT_MANIFEST | 1 | 458 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
The PE file does not contain a certificate table.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Trojan.Win64.Agent.cl without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system