Gridinsoft Logo
File Icon

The S0FTWARE.exe (Adobe AcroCEF) File Analysis

Technical Analysis

File Name S0FTWARE.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
98304:E33JumYT82ylgsN0Nbh0pgnu99UHxh+VU1KSmv+4mn:A8hggIuh+VUvmmn
Scanner Version 1.0.191.174
Database Version 2024-10-07 21:00:54 UTC

Suspicious File Detected

Detected by 32 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
44%
Detection Rate
18,344,960
File Size (bytes)
32/72
Engines Detected
2024-10-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
1603ae955d010896283442534a8ad39c
SHA1
90101b5164c138f227d7add871c1f629bd6d083d
SHA256
34d99b2a6ed62e5080c9448ab3728066c6db5f997212ef71bd2705c79b19fc09
SHA512
e1c8d2ba780d98ff7a845543d35fdf7a2f2092d66295d82cfa07a0d6b64dda58db913967e4f595538f43ac94e88d97e3bfb762205f5588a675ba9abd2ceadb9e
ImpHash
4f2f006e2ecf7172ad368f8289dc96c1

Security Engines with Detections (32 of 72)

Bkav
W32.AIDetectMalware Malicious
Lionic
Trojan.Win32.Crypt.4!c Malicious
Elastic
malicious (high confidence) Malicious
Skyhigh
Artemis Malicious
McAfee
Artemis!1603AE955D01 Malicious
Malwarebytes
Trojan.Dropper.GO.Generic Malicious
K7AntiVirus
Trojan ( 005bab621 ) Malicious
K7GW
Trojan ( 005bab621 ) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of WinGo/TrojanDropper.Agent.ES Malicious
Paloalto
generic.ml Malicious
Kaspersky
Trojan.MSIL.Crypt.ilwp Malicious
Avast
Win32:Malware-gen Malicious
Tencent
Msil.Trojan.Crypt.Cdhl Malicious
F-Secure
Trojan.TR/Crypt.CFI.ndytl Malicious
TrendMicro
TrojanSpy.Win32.VIDAR.YXEJCZ Malicious
McAfeeD
ti!34D99B2A6ED6 Malicious
Trapmine
malicious.moderate.ml.score Malicious
Sophos
Troj/Inject-JQY Malicious
Ikarus
Trojan-Dropper.WinGo.Agent Malicious
Avira
TR/Crypt.CFI.ndytl Malicious
Antiy-AVL
Trojan/Win32.Agent Malicious
Microsoft
Trojan:Win32/Sabsik.FL.A!ml Malicious
ZoneAlarm
Trojan.MSIL.Crypt.ilwp Malicious
Google
Detected Malicious
VBA32
BScope.Backdoor.CoreBot Malicious
TrendMicro-HouseCall
TrojanSpy.Win32.VIDAR.YXEJCZ Malicious
Rising
Dropper.Agent!1.10205 (CLASSIC) Malicious
Fortinet
W32/Agent.ES!tr Malicious
AVG
Win32:Malware-gen Malicious
DeepInstinct
MALICIOUS Malicious
alibabacloud
Trojan[dropper]:Multi/Wacatac.B9nj Malicious
40 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 56441f72aaa09f6ad774a84f30fa1456
Fuzzy: e3fce5895bb09f7fd98e819409e548db
dHash: da2b23cad3d3939a
Image Base 0x00400000
Entry Point 0x00472370
Compilation Time 1970-01-01 00:00:00
Checksum 0x0118e1c7 (Actual: 0x0118e1c7)
OS Version 6.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 1 libraries
kernel32
Exports 0 functions
Resources 12 Resources
Sections 7 Sections

Version Information

CompanyName Adobe Systems Incorporated
EnglishName English
FileDescription Adobe AcroCEF
FileVersion 24.3.20112.0
LanguageId 0409
LegalCopyright Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename AcroCEF.exe
ProductVersion 24.3.20112.0
Signature Read
CompanyName Adobe Systems Incorporated
FileDescription Adobe AcroCEF
FileVersion 24.3.20112.0
LegalCopyright Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename AcroCEF.exe
ProductName Adobe AcroCEF
ProductVersion 24.3.20112.0
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,559,624 bytes 6,559,744 bytes 6.09 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 4D119E60CD3147426C2069793670F56C
.rdata 0x00643000 10,828,664 bytes 10,828,800 bytes 3.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B7A0440B5DCA2E1DF97D9F17938C6962
.data 0x01097000 741,088 bytes 436,736 bytes 5.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CCB44FBD4E1787ABFF08644BC705D992
.idata 0x0114c000 1,118 bytes 1,536 bytes 4.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5B78981F726FADBF9A63D878AA45DAB5
.reloc 0x0114d000 346,564 bytes 346,624 bytes 6.68 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 0CD7F5CF9D041250845C644F4B7276A9
.symtab 0x011a2000 4 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 07B5472D347D42780469FB2654B7FC54
.rsrc 0x011a3000 169,919 bytes 169,984 bytes 1.71 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C98E4C57617CDBD33B1044D8EED2F9D8
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 12 (169,151 bytes)
Resource Type Count Total Size Percentage
RT_ICON 8 165,312 bytes
97.7%
RT_GROUP_ICON 2 124 bytes
0.1%
RT_VERSION 1 1,548 bytes
0.9%
RT_MANIFEST 1 2,167 bytes
1.3%

Certificate Chain Analysis

Certificate Information
Product Adobe AcroCEF
Description Adobe AcroCEF
File Version 24.3.20112.0
Original Name AcroCEF.exe
Copyright Copyright 1984-2024 Adobe Systems Incorporated and its licensors. All rights reserved.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
32 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware