Gridinsoft Logo
File Icon

The WinRAR.exe File Analysis

Technical Analysis

File Name WinRAR.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.217.174
Database Version 2025-06-08 16:00:25 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
13,691,392
File Size (bytes)
2025-06-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
582d3c7b2cd08740b3f5d9791a996066
SHA1
14e6336c15d0bc3fe777bc47678c9def5ea7a296
SHA256
19bb5478158acaa96c7189a65214960499fc0e1dfa10ec2421041bb82c99811d
SHA512
6f7cd4e9579db05d3f5deee5a78339b9da04ab81234dc33273db4da187788886200aca343e9ea84fc26ce19f363fa3c7d38087a21c247ca380fbda4d93b83f3f
ImpHash
c87cd14dd9205199d2ddaad11576f0fd

PE Analysis

Basic Information

Icon
Hash: b3f0266a9874e070b3ec855645687948
Fuzzy: 33d9200afee9550e4e551841fda604a1
dHash: b233333a6b3a3230
Image Base 0x140000000
Entry Point 0x1409e98af
Compilation Time 2025-03-20 10:00:20
Checksum 0x00d0f486 (Actual: 0x00d0f486)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path d:\Projects\WinRAR\build\winrar64\Release\WinRAR.pdb
Digital Signature No valid SignedData structure was found.
Imports 14 libraries
Exports 0 functions
Resources 359 Resources
Sections 10 Sections

Version Information

ProductName WinRAR
CompanyName Alexander Roshal
FileDescription WinRAR
FileVersion 7.11.0
ProductVersion 7.11.0
InternalName WinRAR
LegalCopyright Copyright © Alexander Roshal 1993-2025
OriginalFilename WinRAR.exe
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,024,110 bytes 2,024,448 bytes 6.54 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BD418C8AF69F05D0E86CEBECFD1EAC38
.rdata 0x001f0000 328,658 bytes 328,704 bytes 5.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1F59344A37C0E56607391C3DE9580143
.data 0x00241000 358,620 bytes 45,056 bytes 4.55 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 428116356EE46FE320812E6DCE5C0B91
.pdata 0x00299000 52,896 bytes 53,248 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3C6B8C7D9E89E7F30592A73875EAEDAD
.didat 0x002a6000 304 bytes 512 bytes 2.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C30BB356F9BA6DCFF76290FCF4ED78B3
.D_i 0x002a7000 6,052,029 bytes 6,052,352 bytes 7.74 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 8B59422964C70FE350BC57C291C259E9
.@NY 0x0086d000 5,928 bytes 6,144 bytes 3.05 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 883316A4BFC0386D5E552F5B284AFAFE
.Qwe 0x0086f000 4,328,628 bytes 4,328,960 bytes 7.59 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2865C56D89DBE746694D311A3424B6AD
.reloc 0x00c90000 8,688 bytes 8,704 bytes 5.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AB4B6C9A6AAE1A4C4B9A7468D148E6BF
.rsrc 0x00c93000 841,896 bytes 842,240 bytes 7.15 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AB0A161A55344147988E1FADB2E99A7E
Entropy Analysis Alert

3 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 359 (821,275 bytes)
Resource Type Count Total Size Percentage
PNG 111 432,314 bytes
52.6%
RT_CURSOR 2 1,128 bytes
0.1%
RT_ICON 46 273,645 bytes
33.3%
RT_MENU 2 3,478 bytes
0.4%
RT_DIALOG 83 70,616 bytes
8.6%
RT_STRING 100 36,268 bytes
4.4%
RT_ACCELERATOR 6 544 bytes
0.1%
RT_GROUP_CURSOR 1 34 bytes
0%
RT_GROUP_ICON 6 680 bytes
0.1%
RT_VERSION 1 720 bytes
0.1%
RT_MANIFEST 1 1,848 bytes
0.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware