The lineoff exe (lineoff) Kultisti File Malware Analysis
Gridinsoft Logo
File Icon

The lineoff.exe (lineoff) File Analysis

Technical Analysis

File Name lineoff.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.215.174
Database Version 2025-04-26 01:00:18 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
4,958,720
File Size (bytes)
2025-04-26
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b857ccdfaa944ff262abd1e01cd680a8
SHA1
cd96c8a5e703dc0a9ff61e126b40cc21bbc9ee5c
SHA256
33d82d68fdc66837c972344f09eaea18a2098a7258c617337f89bbf0e2b11f09
SHA512
604709e274199c6d75793c397e9083d75d99642295608240bfe500025a91a5fe25c4d36e3dbb40e80f8d0cc5a0598fb483a8d058fb77131a07b91fe666af327c
ImpHash
4c9c7471868bfe19e05444fa40f84069

PE Analysis

Basic Information

Icon
Hash: dfd383739dba0eb5331633f630b654e2
Fuzzy: d0445e1a6e36bb13a20743fa29a28c3d
dHash: b271c88e666c71b2
Image Base 0x00400000
Entry Point 0x006c801d
Compilation Time 2021-07-21 10:04:24
Checksum 0x004c5d08 (Actual: 0x004bc127)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path c:\hudson\ZeusBase\ZeusGreen\GameMaker\Runner\VC_Runner\Win32\Release-Zeus\Runner.pdb
Digital Signature No valid SignedData structure was found.
Imports 18 libraries
Exports 0 functions
Resources 14 Resources
Sections 8 Sections

Version Information

CompanyName Kultisti
FileDescription lineoff
FileVersion 1.0.0.0
LegalCopyright Kultisti
PrivateBuild 01.00.00.00
ProductName lineoff
ProductVersion 1.0.0.0
Translation 0x0809 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 3,348,324 bytes 3,348,480 bytes 6.63 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3C182FEDA148E873F9F802D4E27A58CE
.rdata 0x00333000 1,013,032 bytes 1,013,248 bytes 5.51 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 667127CC91FD47DDB2C1F490E23C8290
.data 0x0042b000 2,992,736 bytes 547,328 bytes 3.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 530C127AF8F49C69A88E51AF01D0739A
minATL 0x00706000 12 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BF619EAC0CDF3F68D496EA9344137E8B
.mydata 0x00707000 8 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5B71E4C27591CCB21954D71D656B28FB
.gfids 0x00708000 412 bytes 512 bytes 3.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4258A0088C4711F8A29512AFCDB65475
_RDATA 0x00709000 2,016 bytes 2,048 bytes 4.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DB8E2FFAB91D2B70DC34C61ECE8EA31A
.rsrc 0x0070a000 44,768 bytes 45,056 bytes 5.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ CC6E9056B8D3A32349E3123B8A35BC86
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 14 (43,800 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 40,983 bytes
93.6%
RT_DIALOG 5 1,204 bytes
2.7%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 588 bytes
1.3%
RT_MANIFEST 1 1,005 bytes
2.3%

Certificate Chain Analysis

Certificate Information
Product lineoff
Description lineoff
File Version 1.0.0.0
Copyright Kultisti

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware