Gridinsoft Logo
File Icon

SharkHack.exe PUP AI Analysis

Technical Analysis

File Name SharkHack.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-07 15:00:43 UTC

PUP.Win64.AI.cl

Malware family: AI

AI-based detection enhances traditional signature-based antivirus methods by identifying behavioral patterns and anomalies. This approach improves detection of new and polymorphic malware variants that may evade conventional security measures.
N/A
Detection Rate
4,067,328
File Size (bytes)
2025-03-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
de1829af1a22bbf3e19e47a95429801f
SHA1
42984734b1532e8ebd99da16026ed225d1020b19
SHA256
24de9f578a10c496dbed85d9e01a1bae955f317e93717988e39e9049ce4896c2
SHA512
a6eb8339b52b7bda0a135de7b0030a70be1ac2d1e5b0ec344ef27b73ccfc7a51f79be43882554d816164451097d6d111d1ead1b3e827085de7e8fd68d812a098
ImpHash
7d19489b051f7b63e0799521ce3b82f7

PE Analysis

Basic Information

Icon
Hash: 723ceae4e95df37b35f1648f189c8da0
Fuzzy: 6f614ee1358b9bb0812770b51192e36a
dHash: c08639e9e03880c0
Image Base 0x140000000
Entry Point 0x1401f6ee4
Compilation Time 2025-01-05 18:59:52
Checksum 0x00000000 (Actual: 0x003e5555)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 17 libraries
Exports 89 functions
Resources 10 Resources
Sections 7 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,664,448 bytes 2,664,448 bytes 6.28 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D17529C2784399C003036941638B4EA7
.rdata 0x0028c000 475,902 bytes 476,160 bytes 5.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 146C7CEF8E33E5D6F85B2859C23E2245
.data 0x00301000 620,416 bytes 583,168 bytes 7.36 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0ACE8A25103D2D3D99732601165BD37E
.pdata 0x00399000 130,104 bytes 130,560 bytes 6.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B2847C975EFED0ED455BA1A75FA031F1
.fptable 0x003b9000 256 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x003ba000 196,992 bytes 197,120 bytes 6.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EF8454694E7BE937597D3E0657780298
.reloc 0x003eb000 14,276 bytes 14,336 bytes 5.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D43B1A238AB0CFBB4BF9061B7AEF7FF2
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 10 (196,441 bytes)
Resource Type Count Total Size Percentage
RT_ICON 9 196,309 bytes
99.9%
RT_GROUP_ICON 1 132 bytes
0.1%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

PUP.Win64.AI.cl Removal

Gridinsoft has the capability to identify and eliminate PUP.Win64.AI.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware