File Name | Install_Resolve_19.1.4[1].exe |
File Type |
PE32+ executable (GUI) x86-64, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-13 17:00:23 UTC |
Malware family: Downloader
Hash Type | Value | Action |
---|---|---|
MD5 |
2b1b72a4c169370aceba18b422fc36bf
|
|
SHA1 |
f4a00d0529a9424e7576537a549d47640d2c414f
|
|
SHA256 |
32f6f3843bea5710317b1e50846ccb4219753a2170717e70e59fd04bdd64d83b
|
|
SHA512 |
a46a7fa6841df312e96445df8bd226e67045c77ed4a496cf87aae8f98fbed1f52fdc4f29365d5a24b69f30b60e73cdaa20e5109b6fa498eea031d7d987ad28dd
|
|
ImpHash |
f4a4792d62f654b54486ae404c2121ea
|
Icon |
Hash: 02695cede548de9fe03ad87a017b753a
Fuzzy: 6e93ac1a2d6ce076e71c3c7aeac6a949 dHash: e8f6b2b2e8e896f8 |
Image Base | 0x140000000 |
Entry Point | 0x1401637f4 |
Compilation Time | 2025-03-19 17:27:33 |
Checksum | 0x0023b569 (Actual: 0x0023b569) |
OS Version | 6.0 |
PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
Digital Signature | OK |
Imports |
8 libraries
OLEAUT32, USER32, SHELL32, CRYPT32, WS2_32, bcrypt, KERNEL32, ADVAPI32 |
Exports | 0 functions |
Resources | 11 Resources |
Sections | 5 Sections |
CompanyName | Blackmagic Design Pty. Ltd. |
FileDescription | DaVinci Resolve Installer |
FileVersion | 19.1.4.11 |
InternalName | |
LegalCopyright | Copyright (C) 2024 Blackmagic Design Pty. Ltd. |
OriginalFilename | |
ProductName | DaVinci Resolve Installer |
ProductVersion | 19.1.4.11 |
Translation | 0x0c09 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
1,626,304 bytes | 1,626,624 bytes | 6.90 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8F869CEBBC4201BF0653544980D1A91B |
.rdata |
0x0018f000 |
533,416 bytes | 533,504 bytes | 5.69 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
109B327207BE663225ECB4CD1BAB7F67 |
.data |
0x00212000 |
38,152 bytes | 11,264 bytes | 2.92 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A26BD6F16D01AED249C8C09EC41541E2 |
.pdata |
0x0021c000 |
62,688 bytes | 62,976 bytes | 6.06 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
3BAE11527DE9B6EB536FB87D25C9E690 |
.rsrc |
0x0022c000 |
72,960 bytes | 73,216 bytes | 7.36 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
5E575751095742CDAFAA2A7341052528 |
2 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 4 | 69,991 bytes | |
RT_DIALOG | 1 | 184 bytes | |
RT_STRING | 3 | 338 bytes | |
RT_GROUP_ICON | 1 | 62 bytes | |
RT_VERSION | 1 | 796 bytes | |
RT_MANIFEST | 1 | 879 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Trojan.Win64.Downloader.dd!n without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system