Gridinsoft Logo
File Icon

The POP3_Launcher.exe (Prince of Persia T2T Launcher) File Analysis

Technical Analysis

File Name POP3_Launcher.exe
File Type
Win32 EXE
Magic Bytes PE32 executable for MS Windows (GUI) Intel 80386 32-bit
SSDEEP Hash
49152:5w80cTsjkWacavcL4fnWJ533SiO3Q9eHoq:W8sjktvQ4AHIiI
Scanner Version 1.0.210.174
Database Version 2025-03-12 10:00:51 UTC

Suspicious File Detected

Detected by 10 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
15%
Detection Rate
1,967,104
File Size (bytes)
10/67
Engines Detected
2025-03-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
dc8f2d322cd163c3ceb0b5cbc7647838
SHA1
8690e9ccc92c9b45cc25185e02a17e9f26743dea
SHA256
4513b1ee8caa6b6ffb67fe66899dcb43a9ab40bfe2da94ed084830666dcb9087
SHA512
8b7a4ad7abaae144d513ccad8b1c87fbf276b07d73193515e19bec1093c3218374f594d9b68719d45bb5e22fc4a72b6985b84a2d95b5e464fd735b685b1e14cc
ImpHash
649f6ed9a4d576c154bbc0357156a4a4

Security Engines with Detections (10 of 67)

Bkav
W32.AIDetect.malware1 Malicious
Cyren
W32/AutoIt.OH.gen!Eldorado Malicious
McAfee-GW-Edition
BehavesLike.Win32.Generic.tc Malicious
Trapmine
suspicious.low.ml.score Malicious
APEX
Malicious Malicious
McAfee
Artemis!DC8F2D322CD1 Malicious
Malwarebytes
MachineLearning/Anomalous.100% Malicious
Panda
Trj/Genetic.gen Malicious
MaxSecure
Trojan.Malware.300983.susgen Malicious
CrowdStrike
win/malicious_confidence_60% (W) Malicious
57 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 496e94b5103627956f4c47c62c92ef3d
Fuzzy: 1f3968cf833be282166aa59ac375a0bf
dHash: 203a0ed2d29292a6
Image Base 0x00400000
Entry Point 0x00427f4a
Compilation Time 2016-02-27 19:41:33
Checksum 0x001e9a02 (Actual: 0x001e9a02)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 18 libraries
Exports 0 functions
Resources 25 Resources
Sections 5 Sections

Version Information

CompanyName SalFisher47
FileDescription Prince of Persia T2T Launcher
FileVersion 1.1.0.47
InternalName Prince of Persia T2T Launcher
LegalCopyright 2014, SalFisher47
OriginalFilename POP3_Launcher.exe
ProductName Prince of Persia T2T Launcher
ProductVersion 1.1.0.47
Translation 0x0809 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 580,910 bytes 581,120 bytes 6.68 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C2C2260508750422D20CD5CBB116B146
.rdata 0x0008f000 188,686 bytes 188,928 bytes 5.76 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4513B58651E3D8D87C81A396E5B2F1D1
.data 0x000be000 36,724 bytes 20,992 bytes 1.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C2DE4A3D214EAE7E87C7BFC06BD79775
.rsrc 0x000c7000 1,145,500 bytes 1,145,856 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 671F6D1E8E1BF5C41594B3A6D987C8FF
.reloc 0x001df000 28,976 bytes 29,184 bytes 6.78 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 1254908A9A03D2BCF12045D49CD572B9
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 25 (1,144,066 bytes)
Resource Type Count Total Size Percentage
RT_ICON 9 27,368 bytes
2.4%
RT_MENU 1 80 bytes
0%
RT_DIALOG 1 252 bytes
0%
RT_STRING 7 8,900 bytes
0.8%
RT_RCDATA 1 1,105,493 bytes
96.6%
RT_GROUP_ICON 4 150 bytes
0%
RT_VERSION 1 816 bytes
0.1%
RT_MANIFEST 1 1,007 bytes
0.1%

Certificate Chain Analysis

Certificate Information
Product Prince of Persia T2T Launcher
Description Prince of Persia T2T Launcher
File Version 1.1.0.47
Original Name POP3_Launcher.exe
Internal Name Prince of Persia T2T Launcher
Copyright 2014, SalFisher47

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
10 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware