File Name | h2m-revived (2).exe |
File Type |
Win32 EXE
|
Magic Bytes | PE32+ executable (console) x86-64, for MS Windows |
SSDEEP Hash |
98304:yjtYW8rlXVeFGxGD3u4k9sNoJm9+bBX3AtlGGoJXiir7BzN1BNN1BPak+:kYW8ZleFGwa4k9+oJm0GoJxaF
|
Scanner Version | 1.0.185.174 |
Database Version | 2024-08-18 06:00:14 UTC |
Detected by 1 security engines - requires caution
Hash Type | Value | Action |
---|---|---|
MD5 |
e50cbdcfed64dbc438b0170e901a1efe
|
|
SHA1 |
8993bc1deadc7670a60ecdeaf3cd5d7740dba939
|
|
SHA256 |
3375cbf19f872afaa64e78520e73b95e14095ad02f8a36416838395ddcce91f3
|
|
SHA512 |
44d21a9b34f768e9adbc096a3402ab2ca4ab0fcf984f3113d25450dd0c78cbdd712f4dd6bc1c4e1c4dab87d8b33d1cbcf54a5cb02457767c4f94977da2ef7c40
|
|
ImpHash |
a8d4fdf34c62d07e7e3509ec206a4169
|
Icon |
Hash: 45c780829e55a0c3abae065665e8d215
Fuzzy: 37a01ad16fca4f3b9ddabf6be9527493 dHash: 050869eb3b694c03 |
Image Base | 0x160000000 |
Entry Point | 0x160222144 |
Compilation Time | 2024-08-14 14:07:35 |
Checksum | 0x00000000 (Actual: 0x00745efd) |
OS Version | 6.0 |
PEiD Signatures |
PE32+ executable (console) x86-64, for MS Windows
|
PDB Path | F:\cod\Cod Clients\h2m-mod\build\bin\x64\Release\h2m-mod.pdb |
Digital Signature | The PE file does not contain a certificate table. |
Imports | 11 libraries |
Exports | 23 functions |
Resources | 14 Resources |
Sections | 5 Sections |
CompanyName | h2m-mod |
FileDescription | h2m-mod |
FileVersion | 0.0.0.470 |
InternalName | h2m-mod |
LegalCopyright | Copyright © 2024 h2m-mod. All rights reserved. |
Licence | GPLv3 |
Info | https://h2m-mod.dev |
OriginalFilename | h2m-mod.exe |
ProductName | h2m-mod |
ProductVersion | 0.0.0 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
2,525,348 bytes | 2,525,696 bytes | 6.51 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E2AB014B5A1380C82EBE6ECCEA592F05 |
.rdata |
0x0026a000 |
2,700,256 bytes | 2,700,288 bytes | 5.16 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
656B5B0CBEACB975F27F196F59529A38 |
.data |
0x004fe000 |
6,963,704 bytes | 225,792 bytes | 4.13 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
232A5BCF462211BFAE88168AADB9F9C4 |
.pdata |
0x00ba3000 |
90,120 bytes | 90,624 bytes | 6.19 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A0B9B04C903337968D636807C81A846A |
.rsrc |
0x00bba000 |
2,033,504 bytes | 2,033,664 bytes | 5.42 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
1D8658E3D51B5945CE64F41EED92D714 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_BITMAP | 3 | 849,372 bytes | |
RT_ICON | 1 | 270,376 bytes | |
RT_RCDATA | 7 | 911,419 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_VERSION | 1 | 808 bytes | |
RT_MANIFEST | 1 | 641 bytes |
Product | h2m-mod |
Description | h2m-mod |
File Version | 0.0.0.470 |
Original Name | h2m-mod.exe |
Internal Name | h2m-mod |
Copyright | Copyright © 2024 h2m-mod. All rights reserved. |
✓ This file has been digitally signed and the certificate chain has been verified
The PE file does not contain a certificate table.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important