The Sim EKB Install 2019 12 13 exe (Simatic key help) plcforum uz ua File Malware Analysis
Gridinsoft Logo
File Icon

The Sim_EKB_Install_2019_12_13.exe (Simatic key help) File Analysis

Technical Analysis

File Name Sim_EKB_Install_2019_12_13.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.229.174
Database Version 2025-11-30 23:00:37 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,976,704
File Size (bytes)
2025-11-30
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
96b9bdac1535744b5cfba3c036861c86
SHA1
55bf7906cdd2d5ccaaf545677401fc53e6fc8df8
SHA256
46253c63983c347ada18d59d4d5d14cc1596a5f9f5ba355c03165173e24e0847
SHA512
0ff0e0c206fb8dc32c0781c39fc77d996db766f7d6278567d55fda3da8d021a02ac00b67c0ff2eb1332ac7d4a6ed58d616f94818f690164b3c073d44ee44f76e
ImpHash
d868ee9a29f0610773606137f3f876e1

PE Analysis

Basic Information

Icon
Hash: 3b7f343f7bbbf2ed2927bb32a5a0c57c
Fuzzy: f556f203c4aa374525e74e601a0880cf
dHash: 3e9698b86464a4a4
Image Base 0x00400000
Entry Point 0x0072ae84
Compilation Time 2019-12-14 06:19:22
Checksum 0x00000000 (Actual: 0x003d1566)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 13 libraries
Exports 3 functions
Resources 79 Resources
Sections 11 Sections

Version Information

CompanyName plcforum.uz.ua
FileDescription Simatic key help
FileVersion 2015.03.29
ProductVersion 2015.03.29
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 3,305,784 bytes 3,305,984 bytes 6.14 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ FB12DD13D3A8DA030AE1C0C670A8DBB0
.itext 0x00329000 7,964 bytes 8,192 bytes 6.29 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 00D36AF43C0F8D066A0ABEE1DC870491
.data 0x0032b000 139,444 bytes 139,776 bytes 5.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4E690150610399DBDCE1C79C182FD43D
.bss 0x0034e000 5,463,752 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x00884000 15,862 bytes 15,872 bytes 5.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4FDCD67D1091F08A7423C42FDA42E18A
.didata 0x00888000 2,624 bytes 3,072 bytes 3.74 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 19D2BCC9CDE82A60A26887DA17C3D6CE
.edata 0x00889000 165 bytes 512 bytes 2.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ F3092DDAB92F579C697EDAF32976E451
.tls 0x0088a000 76 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x0088b000 93 bytes 512 bytes 1.37 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C71170113909DEDD28FA61B3FB2A0358
.reloc 0x0088c000 288,812 bytes 289,280 bytes 6.66 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 08C6D1A23B1D60E8135ED9499CF82F8D
.rsrc 0x008d3000 212,480 bytes 212,480 bytes 6.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E8550A574B7EC5C0D9868564BE0BE946
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 79 (207,802 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 7 2,156 bytes
1%
RT_BITMAP 26 8,044 bytes
3.9%
RT_ICON 1 744 bytes
0.4%
RT_STRING 28 22,092 bytes
10.6%
RT_RCDATA 7 172,642 bytes
83.1%
RT_GROUP_CURSOR 7 140 bytes
0.1%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 476 bytes
0.2%
RT_MANIFEST 1 1,488 bytes
0.7%

Certificate Chain Analysis

Certificate Information
Description Simatic key help
File Version 2015.03.29

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware