Gridinsoft Logo
File Icon

The GPO Fishing Reborn v2.exe File Analysis

Technical Analysis

File Name GPO Fishing Reborn v2.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.254.174
Database Version 2026-09-22 03:01:19 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
30,995,001
File Size (bytes)
2026-09-22
Analysis Date

Scan Another File

The uploaded file itself is not retained or shared with third parties. File names, hashes, and analysis results may appear in public reports. For confidential material, contact Support before uploading. How we use your data.

File Identification

Hash Type Value Action
MD5
5a5e7f6ca9e94895a1a1c025a8b762e7
SHA1
858b7e9ee7bd6a88ab28b9daad75faee49fd7e2e
SHA256
0e2d1de554fd6bc9c6a81585bfcf9ff52fe215bf207f336c2c4c31eec7c96a3f
SHA512
8b8e3afa1cf5f09a22371d99ea50a1111f2a46aa526b3a99b0e0a3840a08a0968621d3a634e8960fd2218b84f6ac436fd11e3ded9ed1996858722a6cfb9e1bff
ImpHash
e3e80a143805ea18936c8f612e25d363

PE Analysis

Basic Information

Icon
Hash: 45564ff96b4d06b3448c1859b93199a7
Fuzzy: 51795b9c05f101bcfbd2a94df96ca2ff
dHash: 9671694d69b2b292
Image Base 0x140000000
Entry Point 0x14000e770
Compilation Time 2026-09-19 23:29:27
Checksum 0x01d98c40 (Actual: 0x01d98c40)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 5 libraries
USER32, COMCTL32, KERNEL32, ADVAPI32, GDI32
Exports 0 functions
Resources 9 Resources
Sections 7 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 204,800 bytes 204,800 bytes 6.49 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5C1D0671232B92BD70FCD311921F85D8
.rdata 0x00033000 84,308 bytes 84,480 bytes 5.70 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ CCD7AB27AEE2FB92ED536D6D7DCF9464
.data 0x00048000 19,192 bytes 3,584 bytes 1.82 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 954EB046773252153F4899A4EDD122EA
.pdata 0x0004d000 10,092 bytes 10,240 bytes 5.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5BCB3226BA293F62CBCB0C82DFA00C46
.fptable 0x00050000 256 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x00051000 49,068 bytes 49,152 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 301AFFA60ABD996569A8189C370D7A27
.reloc 0x0005d000 1,888 bytes 2,048 bytes 5.25 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ B09B4E3BC6927C160CE8504826E824E7
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 9 (48,533 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 47,136 bytes
97.1%
RT_GROUP_ICON 1 104 bytes
0.2%
RT_MANIFEST 1 1,293 bytes
2.7%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
This file looks clean right now, but that doesn't mean you should let your guard down. New malware appears daily, and even legit files can be compromised after download. When in doubt, verify the source and check for a digital signature.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware