File Name | Setup_10024.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.194.174 |
Database Version | 2024-10-24 15:00:25 UTC |
Malware family: Snackarcin
Hash Type | Value | Action |
---|---|---|
MD5 |
065334948b007f1121d84fa3b8cc036c
|
|
SHA1 |
3fcf60f5f18346cb4cadb36e3bb63aa00f418f8f
|
|
SHA256 |
2c2eb6e8bcd47491ff1e305fb196846a5b07ccdfc23cb8f3c2345a0ae1018e35
|
|
SHA512 |
314d2b20388226567eb229961173dcab93f5e9f3ab8b2307bd3d2a36b3c86f663f025c1b257c6f1957d03072574eae3feca00a3626806f8825b26e0158bd5f4e
|
|
ImpHash |
d514a0a043584816db80d35d2586aa85
|
Icon |
Hash: e8da5abe9752f0a27e183894c8881ac0
Fuzzy: c5dace78993d50eaedeb05b7c48ce608 dHash: 848c5454baf47474 |
Image Base | 0x00400000 |
Entry Point | 0x009981ec |
Compilation Time | 2024-05-26 17:54:49 |
Checksum | 0x04298880 (Actual: 0x04298880) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports |
10 libraries
SHLWAPI, KERNEL32, USER32, SHELL32, OLEAUT32, bcrypt, ADVAPI32, CRYPT32, WLDAP32, WS2_32 |
Exports | 0 functions |
Resources | 9 Resources |
Sections | 5 Sections |
CompanyName | Agreement Tool Tools |
FileDescription | 7-zip Agreement Tool Tools |
FileVersion | 1.0.0.0 |
LegalCopyright | Copyright 2002-2022 Agreement Tool Tools |
ProductName | 7-zip Agreement Tool Tools |
ProductVersion | 1.0.0.0 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
6,357,065 bytes | 6,357,504 bytes | 5.91 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
461511DD62E11F984A617392A597FDC8 |
.rdata |
0x00612000 |
204,924 bytes | 205,312 bytes | 5.73 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
4730FB599A00A5B1BBB8FC5BA12E54AC |
.data |
0x00645000 |
20,296 bytes | 7,680 bytes | 4.24 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
42997E98470ECA6397B5060C77772CCB |
.rsrc |
0x0064a000 |
3,144 bytes | 3,584 bytes | 3.71 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
71DB3EF5564D834A6E8A58ACB8D02DC7 |
.reloc |
0x0064b000 |
73,676 bytes | 73,728 bytes | 6.52 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
60A9949C3FB25AA478FAE4B10A9D2C85 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 2 | 1,040 bytes | |
RT_DIALOG | 1 | 144 bytes | |
RT_STRING | 3 | 232 bytes | |
RT_GROUP_ICON | 1 | 34 bytes | |
RT_VERSION | 1 | 700 bytes | |
RT_MANIFEST | 1 | 381 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.Snackarcin.dd!s1 without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system