File Name | SetupSSuiteNetSurfer.exe |
File Type |
Win32 EXE
|
Magic Bytes | PE32 executable (GUI) Intel 80386, for MS Windows |
SSDEEP Hash |
393216:yiGilNI3HuLbDaXxPij3kmT3QY/jmviOUM6aRLZLl2j46i5YvKnO:yiFlNI3Hc4ijTInlwi5YveO
|
Scanner Version | 1.0.171.174 |
Database Version | 2024-04-08 13:00:25 UTC |
Detected by 3 security engines - requires caution
Hash Type | Value | Action |
---|---|---|
MD5 |
53709f5d66d5ffb3c69fc14f5c2b165b
|
|
SHA1 |
de53a82b8b028a2027e5c1da3d1a26023c06767b
|
|
SHA256 |
3a352ec81a6a89776149902e024540b7a1f944aaa3876b8ba8479a28fa51de47
|
|
SHA512 |
fc62a29b0e22eb835157e4f28553f3d512bd61b2ef9c3cd91698cb85c9befe018f482314d85a1793e2325dedf16de0f19046d03c0dd0a83d2b5d8034ebd5d8df
|
|
ImpHash |
e569e6f445d32ba23766ad67d1e3787f
|
Icon |
Hash: 3267557372130d82b39aab81e0d0a3fb
Fuzzy: fe6b393b23457f26184c297065a9d639 dHash: 70d898ece2fce871 |
Image Base | 0x00400000 |
Entry Point | 0x004b5eec |
Compilation Time | 2023-02-15 14:54:16 |
Checksum | 0x00000000 (Actual: 0x012a9e6a) |
OS Version | 6.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | The PE file does not contain a certificate table. |
Imports |
7 libraries
kernel32, comctl32, version, user32, oleaut32, netapi32, advapi32 |
Exports | 3 functions |
Resources | 26 Resources |
Sections | 10 Sections |
Comments | This installation was built with Inno Setup. |
CompanyName | SSuite Office Software(TM) |
FileDescription | SSuite NetSurfer Browser Setup |
FileVersion | 2.22.6.4 |
LegalCopyright | Copyright© 2000-2037 Van Loo Software™ |
OriginalFileName | |
ProductName | SSuite NetSurfer Browser |
ProductVersion | 2.22.6.4 |
Translation | 0x0000 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
735,716 bytes | 735,744 bytes | 6.36 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
43AF0A9476CA224D8E8461F1E22C94DA |
.itext |
0x000b5000 |
5,768 bytes | 6,144 bytes | 5.97 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
185E04B9A1F554E31F7F848515DC890C |
.data |
0x000b7000 |
14,244 bytes | 14,336 bytes | 5.05 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
CAB2107C933B696AA5CF0CC6C3FD3980 |
.bss |
0x000bb000 |
28,136 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x000c2000 |
4,060 bytes | 4,096 bytes | 5.03 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
E7D1635E2624B124CFDCE6C360AC21CD |
.didata |
0x000c3000 |
420 bytes | 512 bytes | 2.75 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
8CED971D8A7705C98B173E255D8C9AA7 |
.edata |
0x000c4000 |
154 bytes | 512 bytes | 1.88 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8D4E1E508031AFE235BF121C80FD7D5F |
.tls |
0x000c5000 |
24 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x000c6000 |
93 bytes | 512 bytes | 1.38 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8F2F090ACD9622C88A6A852E72F94E96 |
.rsrc |
0x000c7000 |
812,724 bytes | 813,056 bytes | 7.04 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
AB66CC01F95D4909B879C523F3D081E7 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 9 | 798,945 bytes | |
RT_STRING | 11 | 8,040 bytes | |
RT_RCDATA | 3 | 768 bytes | |
RT_GROUP_ICON | 1 | 132 bytes | |
RT_VERSION | 1 | 1,412 bytes | |
RT_MANIFEST | 1 | 1,960 bytes |
Product | SSuite NetSurfer Browser |
Description | SSuite NetSurfer Browser Setup |
File Version | 2.22.6.4 |
Copyright | Copyright© 2000-2037 Van Loo Software™ |
✓ This file has been digitally signed and the certificate chain has been verified
The PE file does not contain a certificate table.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Hendrik van Loo
Apr 08, 2024
It is just a WIN32 web browser that runs on Microsoft's own WebView2 runtime control. We have both 32bit and 64bit versions, and yet the 32bit version gets detected as malware. How do you explain the same two applications getting two different results in anti-virus scanning. Here is the webpage link: ssuiteoffice[.]com/downloads/netsurferwebbrowser.htm If you scan both the 32bit and 64bit versions, you will realize that they are both the same application with different bit size. We have no motive to create malware in our own software.