Gridinsoft Logo
File Icon

The ferrari-virtual-race-0-installer_77Mdq-2.exe (Softonic) File Analysis

Technical Analysis

File Name ferrari-virtual-race-0-installer_77Mdq-2.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
98304:YxyaTy+hd2AEOQCJnF8HRCH+K820ZVP8hcj8CqQFLOAkGkzdnEVomFHKnP9x:YxvTy+dE2n6sRhcj8CPFLOyomFHKnP3
Scanner Version 1.0.218.174
Database Version 2025-06-12 14:00:15 UTC

Suspicious File Detected

Detected by 20 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
28%
Detection Rate
4,518,328
File Size (bytes)
20/71
Engines Detected
2025-06-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
7aca8ccf529e4f7778f5b8919b912f3c
SHA1
774d1f9c45c83425461d1f86c5a98e25dddcfed6
SHA256
1399ed77349aebfeefd34837b25e19e64ec563e16cbba804be66f48edddbc128
SHA512
f4a02de9120fbd86a842ec84bd77bd36ea7d201b9af613aa61af86d94d230e5de2e3492afce639736a6cf70db18e716191d5df8dcb2232c75258d225f8df7e0f
ImpHash
c9fe8df867a04a9054ea77f4c9302945

Security Engines with Detections (20 of 71)

Bkav
W32.Common.D8FC798F Malicious
Lionic
Adware.Win32.CppInstaller.2!c Malicious
CTX
exe.adware.cppinstaller Malicious
McAfee
Artemis!7ACA8CCF529E Malicious
Malwarebytes
PUP.Optional.BundleInstaller Malicious
Zillya
Adware.Agent.Win32.195930 Malicious
K7AntiVirus
Adware ( 005c0bb21 ) Malicious
K7GW
Adware ( 005c0bb21 ) Malicious
VirIT
Deceptor.RisePltInst.EMW Malicious
ESET-NOD32
a variant of Win32/CppInstaller.A potentially unwanted Malicious
Paloalto
generic.ml Malicious
Kaspersky
not-a-virus:HEUR:AdWare.Win32.Agent.gen Malicious
Rising
Adware.Agent!8.71 (CLOUD) Malicious
Google
Detected Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
Ikarus
PUA.CppInstaller Malicious
Varist
W32/OfferCore.AD.gen!Eldorado Malicious
Microsoft
PUADlManager:Win32/OnePlatform Malicious
Cylance
Unsafe Malicious
Fortinet
Riskware/CppInstaller Malicious
51 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 3bb13081559d24c13da756f1077f8274
Fuzzy: 3e9a00f5e503cf72961eb1517b877aee
dHash: 5050d274cecc82aa
Image Base 0x00400000
Entry Point 0x005c6a95
Compilation Time 2024-11-13 14:08:45
Checksum 0x00454f0a (Actual: 0x00454f0a)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\Source\Repos\DS-Platform\CppInstaller\CppSetup\bin\Win32\Release\CppSetup.pdb
Digital Signature OK
Imports 21 libraries
Exports 0 functions
Resources 795 Resources
Sections 5 Sections

Version Information

CompanyName Softonic
FileDescription Softonic
FileVersion 3.0.13.11138
LegalCopyright (c) Softonic
ProductName Softonic
ProductVersion 3.0.13.11138
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,167,872 bytes 2,168,320 bytes 6.55 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ F5F2D9F23294A6293D6E72D0A33C76FA
.rdata 0x00213000 564,834 bytes 565,248 bytes 5.52 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6B948DBE67CB0F6AEE5AF9F48DFF818A
.data 0x0029d000 69,604 bytes 48,128 bytes 5.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 88353E6D17B3B25B78218833C24F730A
.rsrc 0x002ae000 1,550,160 bytes 1,550,336 bytes 7.56 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 235889FC9362891AE84DD058C35AA828
.reloc 0x00429000 174,036 bytes 174,080 bytes 6.57 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ BEA2FD040D93558CA402C06FADEBAAC8
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 795 (1,461,709 bytes)
Resource Type Count Total Size Percentage
AFX_DIALOG_LAYOUT 16 32 bytes
0%
IMAGE_BLOB 1 26,694 bytes
1.8%
IMAGE_BLOB2 1 22,500 bytes
1.5%
IMAGE_BLOB3 1 24,656 bytes
1.7%
LOCALE 17 45,668 bytes
3.1%
PNG 553 1,012,317 bytes
69.3%
STYLE_XML 5 83,741 bytes
5.7%
RT_CURSOR 28 8,496 bytes
0.6%
RT_BITMAP 46 158,460 bytes
10.8%
RT_ICON 21 43,144 bytes
3%
RT_MENU 1 284 bytes
0%
RT_DIALOG 38 18,882 bytes
1.3%
RT_STRING 30 12,804 bytes
0.9%
RT_GROUP_CURSOR 27 554 bytes
0%
RT_GROUP_ICON 5 324 bytes
0%
RT_VERSION 1 572 bytes
0%
RT_MANIFEST 1 2,032 bytes
0.1%
None 3 549 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Softonic
Description Softonic
File Version 3.0.13.11138
Signing Date 02:25 PM 11/13/2024 (213 days ago)
Verification Status Signed
Signers Sigma Gold (Rise Code LTD); Sectigo Public Code Signing CA R36; Sectigo Public Code Signing Root R46; Sectigo (AAA)
Counter Signers Sectigo Public Time Stamping Signer R35; Sectigo Public Time Stamping CA R36; Sectigo Public Time Stamping Root R46
Copyright (c) Softonic
Certificate Chain Summary
Sectigo Public Code Signing Root R46 #1 Primary
Validity Period: 2021-05-25 00:00:00 → 2028-12-31 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
Sectigo Public Time Stamping CA R36 #2 Chain
Validity Period: 2021-03-22 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 7A 23 AE DA 53 69 96 0F 91 C8 3E 5C F4 C7 E3 3F
Sectigo Public Code Signing CA R36 #3 Chain
Validity Period: 2021-03-22 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 62 1D 6D 0C 52 01 9E 3B 90 79 15 20 89 21 1C 0A
Sigma Gold (Rise Code LTD) #4 Chain
Validity Period: 2024-01-29 00:00:00 → 2025-01-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 5E C5 26 F3 4D F3 ED AD E9 36 AE 0C 96 F4 78 BF
Sectigo Public Time Stamping Signer R35 #5 Chain
Validity Period: 2024-01-15 00:00:00 → 2035-04-14 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 3A 52 6A 2C 84 CE 55 E6 1D 65 FC CC 12 D8 E9 89
Sectigo Public Time Stamping Root R46 #6 Chain
Validity Period: 2021-03-22 00:00:00 → 2038-01-18 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 36 C2 B0 BD 7C 1B 3A E7 A3 B3 DD 36 CB C9 75 68

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
20 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware