Gridinsoft Logo
File Icon

The global_mapper.exe (Global Mapper 25.0) File Analysis

Technical Analysis

File Name global_mapper.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
786432:aH704jiCdRGSgPlSOPl7HLkYKQpqt/vL5br3HamSUz1DuEH5cYUn:ao4moHR+kzb5f36mSo1DZ2
Scanner Version 1.0.147.174
Database Version 2023-11-15 06:03:47 UTC

Suspicious File Detected

Detected by 8 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
11%
Detection Rate
47,841,408
File Size (bytes)
8/70
Engines Detected
2023-11-15
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
064ad65117d6cc5a703face8dbe020d2
SHA1
164c0f5cbe354d55589546f0739ac4e96564e940
SHA256
242cf5f27e325dea24b9630b78b3dadb7db0df94c760adf0fb134c31abe614e7
SHA512
cbb9cbd84a397d2878e659442db5a1db37c167f3134ca78abf30671569ba19c6090b289d4bb43b34641f527781ae49480aaf3feb39b51444aef8b291acf59aa1
ImpHash
0452f7d2f772d38062e7c3cef8856643

Security Engines with Detections (8 of 70)

Elastic
malicious (moderate confidence) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of Win64/Packed.Enigma.BV Malicious
Trapmine
suspicious.low.ml.score Malicious
Ikarus
Trojan.Win64.Enigma Malicious
Microsoft
Program:Win32/Wacapew.C!ml Malicious
Google
Detected Malicious
Zoner
Probably Heur.ExeHeaderL Malicious
62 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 357c7d1c976253d2b766bc8514c29edf
Fuzzy: b05ef06b143c89dfd0ddb3311b1ca29c
dHash: 23913961630d330f
Image Base 0x140000000
Entry Point 0x146c994ec
Compilation Time 2023-10-23 13:39:11
Checksum 0x053ce159 (Actual: 0x02da8e92)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 100 libraries
Exports 3542 functions
Resources 2052 Resources
Sections 10 Sections

Version Information

CompanyName Blue Marble Geographics
FileDescription Global Mapper 25.0
FileVersion 25.0
InternalName Global Mapper
LegalCopyright Copyright © 2002-2023
OriginalFilename global_mapper.exe
ProductName Global Mapper 25.0
ProductVersion 25.0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 54,669,312 bytes 21,882,880 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FBED84CED8CA884AC867189283156271
0x03424000 1,200,128 bytes 329,728 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE DD07CD18B27F5F34C59BA67BBDD17F98
0x03549000 18,776,064 bytes 6,960,128 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C6A2E48E94334A4ABA11602EA97F65E9
0x04731000 8,634,368 bytes 313,344 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 921443B5705DE267B94CC5E9A01F4C3A
0x04f6d000 1,572,864 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x050ed000 53,248 bytes 32,256 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 64978657D281786160DD4A2060DF232D
0x050fa000 10,133,504 bytes 4,354,560 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F6970FDADCEABB31208D958D76D555C8
.rsrc 0x05aa4000 1,867,776 bytes 1,867,264 bytes 3.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 94E8A7707839F936534AD09C3730FFD8
0x05c6c000 12,042,240 bytes 7,162,880 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2044B78B36FA0E961243F559FC072E91
0x067e8000 4,927,488 bytes 4,927,488 bytes 7.79 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 17B816F90B798ABCCA7A67BA672DFC4D
Entropy Analysis Alert

8 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 2052 (10,023,346 bytes)
Resource Type Count Total Size Percentage
AFX_DIALOG_LAYOUT 310 1,332 bytes
0%
PNG 425 2,655,064 bytes
26.5%
RT_CURSOR 47 184,172 bytes
1.8%
RT_BITMAP 71 3,507,400 bytes
35%
RT_ICON 22 483,500 bytes
4.8%
RT_MENU 11 47,212 bytes
0.5%
RT_DIALOG 537 707,512 bytes
7.1%
RT_STRING 427 571,632 bytes
5.7%
RT_ACCELERATOR 1 464 bytes
0%
RT_GROUP_CURSOR 47 940 bytes
0%
RT_GROUP_ICON 10 368 bytes
0%
RT_VERSION 1 764 bytes
0%
RT_HTML 11 1,846,577 bytes
18.4%
RT_MANIFEST 1 1,150 bytes
0%
None 131 15,259 bytes
0.2%

Certificate Chain Analysis

Certificate Information
Product Global Mapper 25.0
Description Global Mapper 25.0
File Version 25.0
Original Name global_mapper.exe
Internal Name Global Mapper
Copyright Copyright © 2002-2023
Certificate Chain Summary
tg167A8DE #1 Primary
Validity Period: 2019-11-20 09:58:24 → 2029-11-19 09:58:24
Signature Algorithm: sha256RSA
Serial Number: 1E B5 FF 4C 25 2B 2B A1 45 83 8E C0 7A FA CD 29 6F 57 95 99
Enigma Protector CA #2 Chain
Validity Period: 2019-02-05 16:34:15 → 2039-02-05 16:34:15
Signature Algorithm: sha256RSA
Serial Number: 2C ED 5C 2C 5D B4 B7 06 CF DF 0F 49 77 45 62 80 4F DC 00 C7
DigiCert SHA2 Assured ID Code Signing CA #3 Chain
Validity Period: 2013-10-22 12:00:00 → 2028-10-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08
Blue Marble Geographics #4 Chain
Validity Period: 2021-02-22 00:00:00 → 2024-03-07 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0A 29 61 6D F9 7C DE 0D C4 62 9D 5E 97 AB E3 30
DigiCert Timestamp 2023 #5 Chain
Validity Period: 2023-07-14 00:00:00 → 2034-10-13 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 05 44 AF F3 94 9D 08 39 A6 BF DB 3F 5F E5 61 16
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #6 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #7 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
8 security engines flagged this file. Could be a real threat, or could be a false alarm — common with keygens, game trainers, and legitimate system utilities. Check if the file has a valid digital signature and whether it came from the official source.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware