Gridinsoft Logo
File Icon

The Leitostrap.exe File Analysis

Technical Analysis

File Name Leitostrap.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
SSDEEP Hash
786432:Eaav4znyXDrb2VEnAcqwnQ3elMUtEqefBz96:EZ72VE9EqwP6
Scanner Version 1.0.247.174
Database Version 2026-06-08 01:00:36 UTC

Suspicious File Detected

Detected by 7 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
10%
Detection Rate
48,427,008
File Size (bytes)
7/71
Engines Detected
2026-06-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
3ac997f0966de96190b51520c585411d
SHA1
d703e1a9aa63875c0348242cd8bfc4e7aa1809b6
SHA256
4906bd3887b20cd655c34ed454a535310936a7936eec9d323fdc5edb264f65fb
SHA512
813a50f429579ad391f4707634ddfed8e3bf589658dd8c2815119def3a0ad1ce8bff305bc7f6c3a15adfce07e66111c79664691265057ab197a66dc19922c5a6
ImpHash
ed177619e59ccf4a0672232f20cd956e

Security Engines with Detections (7 of 71)

Bkav
W32.Malware.2EAD7632 Malicious
CrowdStrike
win/malicious_confidence_70% (D) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Elastic
malicious (high confidence) Malicious
McAfeeD
ti!4906BD3887B2 Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
DeepInstinct
MALICIOUS Malicious
64 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 5e7b723d937fc12aef22bd25430973cf
Fuzzy: 276476e3133115d3d9d06e96d15f67e0
dHash: d022327a91b39ac0
Image Base 0x140000000
Entry Point 0x140001017
Compilation Time 2026-06-07 19:49:57
Checksum 0x02e0d094 (Actual: 0x02e3512d)
OS Version 4.0
PEiD Signatures PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
KERNEL32, msvcrt, SHELL32
Exports 0 functions
Resources 9 Resources
Sections 11 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 58,160 bytes 58,368 bytes 6.06 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 44BC65FB7634BC5446ED6C5CE1C403F1
.data 0x00010000 384 bytes 512 bytes 1.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 687E5C6F0FA760F7734DCE4E45E8D316
.rdata 0x00011000 48,217,176 bytes 48,217,600 bytes 6.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D2139B1CE71CEDEAB502313959D30E72
.eh_fram 0x02e0d000 4 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.pdata 0x02e0e000 2,004 bytes 2,048 bytes 5.09 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7D42B5C7F057B88AB983DB0848EA4A45
.xdata 0x02e0f000 2,124 bytes 2,560 bytes 3.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 040EBCDA7062277224C7D54F78D273F1
.bss 0x02e10000 169,056 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x02e3a000 3,912 bytes 4,096 bytes 4.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9EA0F72653E9CF7D8A9277DA7DB38FDC
.tls 0x02e3b000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x02e3c000 139,052 bytes 139,264 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1EA4CBFD26BEB1CEDB7AC05E48680AB9
.reloc 0x02e5e000 136 bytes 512 bytes 1.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 804CB4515A6B4F3A21C0F01D452C033A
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 9 (138,521 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 137,152 bytes
99%
RT_GROUP_ICON 1 104 bytes
0.1%
RT_MANIFEST 1 1,265 bytes
0.9%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
7 security engines flagged this file. Could be a real threat, or could be a false alarm — common with keygens, game trainers, and legitimate system utilities. Check if the file has a valid digital signature and whether it came from the official source.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware