Gridinsoft Logo

The Stub.exe File Analysis

Technical Analysis

File Name Stub.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
SSDEEP Hash
1536:t2Fhvk7JknoDR58tXwL6cgue6rsgE8PU6aivQZIE6EXb/lCzyRkmma3tS8rTTRKx:t2FhvkNkgE8PU6aivfE/XbNOIkmTrox
Scanner Version 1.0.138.174
Database Version 2023-09-13 22:07:07 UTC

Suspicious File Detected

Detected by 43 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
61%
Detection Rate
66,560
File Size (bytes)
43/71
Engines Detected
2023-09-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
71350265ce9a9650b2881c7b444a24d9
SHA1
8e6a91f8243b6b1f19d8168694456a810c7fd2f7
SHA256
3f4fd2769bc0d88074a6df3409a1f86fe5073e1cc4d57e84d5a322f0d7240127
SHA512
13d79398657909266b6494e0ce688805844ace9b96f2d381f0623c9cce33f689074f0f2051d696bcc04537035f03a8e591fa5a15a33cc99c621ddb7b53e123ac
ImpHash
f34d5f2d4577ed6d9ceec516c1f5a744

Security Engines with Detections (43 of 71)

MicroWorld-eScan
IL:Trojan.MSILZilla.24027 Malicious
ClamAV
Win.Packed.Razy-9625918-0 Malicious
ALYac
IL:Trojan.MSILZilla.24027 Malicious
Malwarebytes
Backdoor.AsyncRAT Malicious
Sangfor
Trojan.Win32.Save.a Malicious
Cybereason
malicious.8243b6 Malicious
VirIT
Trojan.Win32.MSIL_Heur.B Malicious
Cyren
W32/Samas.B.gen!Eldorado Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Elastic
Windows.Trojan.Asyncrat Malicious
ESET-NOD32
a variant of MSIL/Agent.CFQ Malicious
APEX
Malicious Malicious
Cynet
Malicious (score: 100) Malicious
Kaspersky
HEUR:Trojan-Banker.MSIL.ClipBanker.gen Malicious
BitDefender
IL:Trojan.MSILZilla.24027 Malicious
Avast
Win32:DropperX-gen [Drp] Malicious
Emsisoft
IL:Trojan.MSILZilla.24027 (B) Malicious
F-Secure
Trojan.TR/Dropper.Gen Malicious
DrWeb
BackDoor.AsyncRATNET.2 Malicious
VIPRE
IL:Trojan.MSILZilla.24027 Malicious
McAfee-GW-Edition
BehavesLike.Win32.Generic.km Malicious
FireEye
Generic.mg.71350265ce9a9650 Malicious
Sophos
Troj/AsyncRat-B Malicious
Ikarus
Trojan.MSIL.Agent Malicious
GData
IL:Trojan.MSILZilla.24027 Malicious
Avira
TR/Dropper.Gen Malicious
Arcabit
IL:Trojan.MSILZilla.D5DDB Malicious
ZoneAlarm
HEUR:Trojan-Banker.MSIL.ClipBanker.gen Malicious
Microsoft
Backdoor:MSIL/AsyncRat.AD!MTB Malicious
Google
Detected Malicious
AhnLab-V3
Malware/Win.Generic.C4980844 Malicious
McAfee
Trojan-FVQO!71350265CE9A Malicious
MAX
malware (ai score=89) Malicious
VBA32
OScope.Backdoor.MSIL.Crysan Malicious
Cylance
unsafe Malicious
Rising
Trojan.AntiVM!1.CF63 (CLASSIC) Malicious
SentinelOne
Static AI - Malicious PE Malicious
MaxSecure
Trojan.Malware.300983.susgen Malicious
Fortinet
MSIL/Agent.CFQ!tr Malicious
BitDefenderTheta
Gen:NN.ZemsilF.36662.em0@aOZNS6j Malicious
AVG
Win32:DropperX-gen [Drp] Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/malicious_confidence_100% (W) Malicious
28 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004115fe
Compilation Time 2023-09-12 18:46:51
Checksum 0x00000000 (Actual: 0x00015a57)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 1 libraries
mscoree
Exports 0 functions
Resources 2 Resources
Sections 3 Sections

Version Information

Translation 0x0000 0x04b0
Comments
CompanyName
FileDescription
FileVersion 1.0.0.0
InternalName Stub.exe
LegalCopyright
LegalTrademarks
OriginalFilename Stub.exe
ProductName
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00002000 62,980 bytes 63,488 bytes 5.59 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 49DC7B20A223036AE6361A54DC964309
.rsrc 0x00012000 2,047 bytes 2,048 bytes 4.88 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 33CDBC5C50F34A35B4F0E61582AC7F11
.reloc 0x00014000 12 bytes 512 bytes 0.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 16F12256668E1C441A8910608B5ECFF1

Resource Analysis

Total Resources: 2 (1,887 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 716 bytes
37.9%
RT_MANIFEST 1 1,171 bytes
62.1%

Certificate Chain Analysis

Certificate Information
File Version 1.0.0.0
Original Name Stub.exe
Internal Name Stub.exe

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
43 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware