Gridinsoft Logo
File Icon

The Setup - Bloxshade.exe (Bloxshade Installer (developed by Extravi, https://extravi.dev/)) File Analysis

Technical Analysis

File Name Setup - Bloxshade.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.220.174
Database Version 2025-07-09 04:00:31 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
12,355,648
File Size (bytes)
2025-07-09
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
449aca1252c5e904125964b1259ce66c
SHA1
dacbe44a2f4c7abed7fb93aea83fd9b16494169a
SHA256
1b727cd6e9b6277488dcdab44492b213063f4d303cad92fa7b58b683b4359e46
SHA512
2f7f949c899dc1ed2816111a92eba9bc797c08c67aca5ce47928ef5db7834e2f052f4a995db099d40b710f82103ac0534b761c0352aadb016445cb92d7eef612
ImpHash
7e3f32db6c2b3488239895398f145e44

PE Analysis

Basic Information

Icon
Hash: 74cd592a5a6e96c2a24d6525c3d84595
Fuzzy: 57cfc064fa15c32b45a5a49048dae861
dHash: d4d8d4dcc0c0c8d9
Image Base 0x140000000
Entry Point 0x14004a870
Compilation Time 2025-06-29 00:59:39
Checksum 0x00bd062b (Actual: 0x00bd062b)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path C:\Users\hecker\Desktop\Bloxshade-main\bloxshade\build\start.pdb
Digital Signature Chain verification from CN=Extravi, [email protected], O=extravi.dev (serial:95195809747272595128136162848617863741, sha1:efd8afbc49ea94192bd8f68edde3e291d18e94fe) failed: The X.509 certificate provided is self-signed - "Common Name: Extravi, Email Address: [email protected], Organization: extravi.dev"
Imports 4 libraries
KERNEL32, USER32, ADVAPI32, SHELL32
Exports 0 functions
Resources 13 Resources
Sections 7 Sections

Version Information

Comments Website: https://extravi.dev/
CompanyName Website: https://extravi.dev/
FileDescription Bloxshade Installer (developed by Extravi, https://extravi.dev/)
FileVersion 2.8.17.0
InternalName Bloxshade
LegalCopyright Copyright © 2025 Extravi
OriginalFilename Setup - Bloxshade.exe
ProductName Bloxshade
ProductVersion 2.8.17.0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 725,110 bytes 725,504 bytes 5.72 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ DD6CD97F2304935395664EF44D47FF13
.rdata 0x000b3000 162,598 bytes 162,816 bytes 4.52 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C586421FD967B879CE1C50AF1D06E31C
.data 0x000db000 16,580 bytes 8,192 bytes 3.62 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 47BE3A42332E78E097A385EDE49C7C8A
.pdata 0x000e0000 33,960 bytes 34,304 bytes 5.74 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 022C6859FCEBE9B6377778C183951D81
.fptable 0x000e9000 256 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x000ea000 11,411,520 bytes 11,411,968 bytes 7.07 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4AFED8B596F3176D9BEFB49579A591F6
.reloc 0x00bcd000 3,660 bytes 4,096 bytes 5.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ DF1619A02B613C9E24AC1F13B976AA6E
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 13 (11,410,704 bytes)
Resource Type Count Total Size Percentage
BINARY 4 11,369,640 bytes
99.6%
RT_ICON 6 39,630 bytes
0.3%
RT_GROUP_ICON 1 90 bytes
0%
RT_VERSION 1 952 bytes
0%
RT_MANIFEST 1 392 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Bloxshade
Description Bloxshade Installer (developed by Extravi, https://extravi.dev/)
File Version 2.8.17.0
Original Name Setup - Bloxshade.exe
Signing Date 01:01 AM 06/29/2025 (15 days ago)
Verification Status A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
Signers Extravi
Internal Name Bloxshade
Copyright Copyright © 2025 Extravi
Certificate Chain Summary
Extravi #1 Primary
Validity Period: 2024-06-02 04:45:07 → 2104-06-02 04:55:07
Signature Algorithm: sha256RSA
Serial Number: 47 9E 0B CA 68 5E 6D 8A 42 FA 23 22 17 59 1A 3D
Sectigo Public Time Stamping CA R36 #2 Chain
Validity Period: 2021-03-22 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 7A 23 AE DA 53 69 96 0F 91 C8 3E 5C F4 C7 E3 3F
Sectigo Public Time Stamping Signer R36 #3 Chain
Validity Period: 2025-03-27 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: A4 29 3B 6E 1E DD D7 A7 34 08 87 AD 7A 4E B7 24
Sectigo Public Time Stamping Root R46 #4 Chain
Validity Period: 2021-03-22 00:00:00 → 2038-01-18 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 36 C2 B0 BD 7C 1B 3A E7 A3 B3 DD 36 CB C9 75 68

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

Chain verification from CN=Extravi, [email protected], O=extravi.dev (serial:95195809747272595128136162848617863741, sha1:efd8afbc49ea94192bd8f68edde3e291d18e94fe) failed: The X.509 certificate provided is self-signed - "Common Name: Extravi, Email Address: [email protected], Organization: extravi.dev"

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware