Gridinsoft Logo
File Icon

The 洛水.EXE (洛水.exe) File Analysis

Technical Analysis

File Name 洛水.EXE
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
196608:RIqorr3HxYqSChTD2kgZnXJ2j4wLOYDLRe1w2sbUbzoUZuPxuL9Sa7oX+dCu:6qorr3HNDKaRLO+ReybUbzS4LYa7Rt
Scanner Version 1.0.229.174
Database Version 2025-12-02 09:00:43 UTC

Suspicious File Detected

Detected by 14 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
19%
Detection Rate
14,097,408
File Size (bytes)
14/72
Engines Detected
2025-12-02
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6b210ea99f1192bd4f6c17e0858b1fca
SHA1
e6e5ac72b44452233173cbf7442f0deba25eed31
SHA256
22add24cd87a2af8bceb617c2a5979926325b7187f9141bbcad9d67d551b468e
SHA512
c4499dd025f5b4d83844f53aa16d13849a503b50d83b9f07b9601a7745d734c69841db5b683b17873b8a0f146f93778656a35d155d911eea83d1f663e87bf0b1
ImpHash
18cc960925e8468abe2bad7b12f031be

Security Engines with Detections (14 of 72)

Bkav
W64.AIDetectMalware Malicious
Skyhigh
BehavesLike.Win64.Backdoor.tc Malicious
CrowdStrike
win/malicious_confidence_90% (D) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Elastic
malicious (high confidence) Malicious
APEX
Malicious Malicious
Google
Detected Malicious
Zillya
Trojan.Stealer.Win32.199931 Malicious
McAfeeD
ti!22ADD24CD87A Malicious
Trapmine
malicious.moderate.ml.score Malicious
SentinelOne
Static AI - Suspicious PE Malicious
Ikarus
Trojan.Win64.Agent Malicious
AVG
Win64:MalwareX-gen [Trj] Malicious
Avast
Win64:MalwareX-gen [Trj] Malicious
58 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 01be34f9719e98987ee6457dd608dbb8
Fuzzy: 574c67fd8cd6dcdf8e1520523be1b2be
dHash: b0f0e8f0b2b2aa69
Image Base 0x140000000
Entry Point 0x14000c964
Compilation Time 2025-11-18 09:00:20
Checksum 0x00000000 (Actual: 0x00d7d2fc)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 2 libraries
SHELL32, KERNEL32
Exports 0 functions
Resources 5 Resources
Sections 7 Sections

Version Information

ProductVersion 1.4.5.0
FileVersion 1.4.5.0
OriginalFilename 洛水.exe
InternalName 洛水
ProductName 洛水
FileDescription 洛水.exe
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 142,640 bytes 142,848 bytes 6.50 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ EB5C41A63008B8C77FAEECFB6C984D7F
.rdata 0x00024000 52,994 bytes 53,248 bytes 5.17 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D3B89D08327319DAB2D154EC4470605E
.data 0x00031000 167,264 bytes 3,072 bytes 1.96 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9F76BB582FC483F48C3EDB9A0807AAA3
.pdata 0x0005a000 6,444 bytes 6,656 bytes 5.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BD605D98E28F645B38355802D3F0FC45
.fptable 0x0005c000 256 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0005d000 13,887,600 bytes 13,888,000 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9C535186C5F95F749C1FE188E0F732F8
.reloc 0x00d9c000 1,672 bytes 2,048 bytes 4.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 85089BAFDC656B927261807CB5FE672B
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 5 (13,887,221 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 266,152 bytes
1.9%
RT_RCDATA 1 13,619,272 bytes
98.1%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 512 bytes
0%
RT_MANIFEST 1 1,265 bytes
0%

Certificate Chain Analysis

Certificate Information
Product 洛水
Description 洛水.exe
File Version 1.4.5.0
Original Name 洛水.exe
Internal Name 洛水

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
14 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware