Please ensure you understand and agree with our data protection policy before using this site. Review Policy
Online Virus Checker | v.1.0.173.174 |
DB Version: | 2024-04-27 07:00:17 |
Packing is a common tactic used by malware authors to make their malicious code more difficult to analyze and detect by antivirus and security programs. These techniques involve compressing, encrypting, or otherwise altering the malware's code to make it appear different from its original form. The goal is to hide the true nature of the malware from security tools.
File | Synthesia.exe |
Checked | 2024-04-27 07:13:48 |
MD5 | 839cb18f4698e59b2c08bbb70a6417dd |
SHA1 | 1c99075a4599d4fdfede0eabee67c057017fa630 |
SHA256 | 2c55cd81903c0cb5d8a6bd5a63c6801540f17ae2dbf09723f4f0bef2fe0f9d0f |
SHA512 | 0f89ecae2bad5bc23166815941e4015ecdcfee6897905b13ecb2f84033de699196ffa4f094ca33b3d051550088c698ba5c958d2a53312705756ee27f7fd87777 |
Imphash | 5dab2c5f9ee471d15897d0efa91b054d |
File Size | 15897600 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Win64.Packed.cl without requiring further user intervention.
FileDescription | Synthesia |
LegalCopyright | (c)2022 Synthesia LLC |
ProductName | Synthesia |
ProductVersion | 10.9 |
Translation | 0x0409 0x0025 |
1a4d70978548798b2d58c56d3232d14f 8a10ea84ebad8240b634a98c21dc3542 e4e4ece8c8da9ad8 |
|
Image Base: | 0x140000000 |
Entry Point: | 0x1409be5cc |
Compilation: | 2022-12-21 23:47:41 |
Checksum: | 0x00f2f714 (Actual: 0x00f2f714) |
OS Version: | 6.0 |
PDB Path: | C:\TeamCityAgent\work\f71b18c76256d81b\build\win\x64\Release\Synthesia.pdb |
PEiD: | PE32+ executable (GUI) x86-64, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 9 |
Imports: | WINMM, KERNEL32, USER32, SHELL32, VERSION, SETUPAPI, WS2_32, dbghelp, WININET, WINHTTP, OPENGL32, gdiplus, GDI32, ADVAPI32, ole32, bcrypt, |
Exports: | 0 |
Resources: | 296 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x003fdd1c | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rdata | 0x003ff000 | 0x000de942 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.data | 0x004de000 | 0x0003bb64 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.pdata | 0x0051a000 | 0x00028488 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
_RDATA | 0x00543000 | 0x0000015c | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.vmp0 | 0x00544000 | 0x0014e68c | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.vmp1 | 0x00693000 | 0x00f04a70 | 0x00f04c00 | 43a9765c870431dd32dc6845f4a10b7f | 7.98 |
.reloc | 0x01598000 | 0x000000d4 | 0x00000200 | 48c6cda9dcefe248e21d26c8c7614d6e | 2.34 |
.rsrc | 0x01599000 | 0x00dfe68e | 0x00024200 | 551aa4466201620bc2eb11f114c0b057 | 5.06 |