Gridinsoft Logo
File Icon

The FeatherWalletSetup-2.8.1.exe File Analysis

Technical Analysis

File Name FeatherWalletSetup-2.8.1.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
SSDEEP Hash
393216:XE2/90I9mbQIgy2694Y+FhB+jH9ao0tPmcj629qxiSNUh2OHddtZ3y:XjMR2i/+Fujda4wXsePHddy
Scanner Version 1.0.218.174
Database Version 2025-06-21 13:00:27 UTC

Suspicious File Detected

Detected by 20 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
28%
Detection Rate
20,057,816
File Size (bytes)
20/72
Engines Detected
2025-06-21
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
5410eafa097b62ec688eb531084eadfc
SHA1
15085d4e3864548a0563436bd1025224bd98a567
SHA256
2763a246ffe6cf0aef290c4344fc12de33582d4fa834b0049e4deb7daa5eb529
SHA512
ff8780a44b78f332061b8d3d9a75553c9921d3396de8f27ca15b2861ce9584dae5866b6bce2d50fbfca6f76ab8f762129bd2143afea5505be7e89c6b454b1ca5
ImpHash
582835fdfe878b98ae0447faa0dff42b

Security Engines with Detections (20 of 72)

Lionic
Adware.Win32.Generic.2!c Malicious
AVG
Win64:MalwareX-gen [Misc] Malicious
CAT-QuickHeal
Trojan.Ghanarava.17495027074eadfc Malicious
Skyhigh
Artemis Malicious
Cylance
Unsafe Malicious
K7GW
Adware ( 00569ecc1 ) Malicious
K7AntiVirus
Adware ( 00569ecc1 ) Malicious
ESET-NOD32
a variant of Win64/CoinMiner.NN potentially unwanted Malicious
Avast
Win64:MalwareX-gen [Misc] Malicious
CTX
exe.miner.artemis Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
Varist
W64/ABApplication.HBVG-4282 Malicious
Kingsoft
Win32.Troj.pomal.v Malicious
Microsoft
Trojan:Win32/Pomal!rfn Malicious
Google
Detected Malicious
TrellixENS
Artemis!5410EAFA097B Malicious
MaxSecure
Trojan.Malware.216124210.susgen Malicious
Fortinet
Adware/Miner Malicious
DeepInstinct
MALICIOUS Malicious
alibabacloud
Miner:Win/CoinMiner.CG Malicious
52 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: e075bebfd99959b5d527f885a4e7ade7
Fuzzy: be292506691d611c99f5eb73afa32305
dHash: c46071b9583c2908
Image Base 0x140000000
Entry Point 0x140003e80
Compilation Time 1970-01-01 00:00:01
Checksum 0x0132ee44 (Actual: 0x0132ee44)
OS Version 4.0
PEiD Signatures PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Digital Signature OK
Imports 7 libraries
ADVAPI32, COMCTL32, GDI32, KERNEL32, ole32, SHELL32, USER32
Exports 0 functions
Resources 15 Resources
Sections 9 Sections

Version Information

CompanyName Feather Wallet
CompanyWebsite https://featherwallet.org
FileDescription Installer for Feather Wallet
FileVersion 2.8.1
LegalCopyright Copyright (C) 2020-2025 The Monero Project
ProductName Feather Wallet
ProductVersion 2.8.1
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 33,024 bytes 33,280 bytes 6.26 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ F1AE150149C1FA19551570CD278577D5
.data 0x0000a000 320 bytes 512 bytes 1.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 79D9C35A8A8E6862BB19637AD5EBE817
.rdata 0x0000b000 53,376 bytes 53,760 bytes 6.92 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BB9CA2B4E6AB35FE932274E8785ACF0E
.xdata 0x00019000 1,140 bytes 1,536 bytes 3.62 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 290EA83B33E7AF5C3CDCD34862EA8D32
.pdata 0x0001a000 1,212 bytes 1,536 bytes 3.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C9B2F0B30F9D0326C382AA230EBAB8BB
.bss 0x0001b000 123,648 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x0003a000 6,400 bytes 6,656 bytes 4.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 68E32350300FC117F09CC4DB05DCCB41
.ndata 0x0003c000 159,744 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x00063000 41,104 bytes 41,472 bytes 6.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D56D6B7A9FC1AC85814766516366B95B
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 15 (40,233 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 36,744 bytes
91.3%
RT_DIALOG 5 1,556 bytes
3.9%
RT_GROUP_ICON 1 104 bytes
0.3%
RT_VERSION 1 752 bytes
1.9%
RT_MANIFEST 1 1,077 bytes
2.7%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
20 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware