Gridinsoft Logo
File Icon

The sora_1st.exe File Analysis

Technical Analysis

File Name sora_1st.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.226.174
Database Version 2025-09-30 02:00:26 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
9,931,776
File Size (bytes)
2025-09-30
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
5e7e73fdc9f9b188f58c5a7fc47e577c
SHA1
7b623d353702fc7d5133bf207b5970467482e73c
SHA256
4f84cb3be200cfd0485d9d6b2fec0ba70a63d73d3fb8a29a515e3a7abdbf13cf
SHA512
5d87e753ae02f82efffd1cd2e0244c5b1927838acc4b76909bea65962548bde18db76f1e5da384390804e5720544b623b5a2a0ce05df8e734eb00320718dfd5a
ImpHash
d4fd014392daa52cf9b0851525695d20

PE Analysis

Basic Information

Icon
Hash: 7a829b35d18278eb131feea160616557
Fuzzy: 340b0cf0149164f12b16e3b184f62936
dHash: 98ac292d72f4d69b
Image Base 0x140000000
Entry Point 0x14069a1c4
Compilation Time 2025-09-18 06:19:21
Checksum 0x00000000 (Actual: 0x009817db)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path d:\JenkinsRemoteFS\workspace\sora_steam\bin\sora_deploy_steam.pdb
Digital Signature No valid SignedData structure was found.
Imports 10 libraries
USER32, steam_api64, XAudio2_9, d3d11, dxgi, XINPUT1_4, KERNEL32, SHELL32, ole32, IMM32
Exports 0 functions
Resources 8 Resources
Sections 6 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 7,803,801 bytes 7,803,904 bytes 6.45 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ A61F5661706284B08D6F8820DE27C113
.rdata 0x00773000 1,342,884 bytes 1,342,976 bytes 5.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 20562DD68EB80AE9334393326967802D
.data 0x008bb000 280,052 bytes 259,072 bytes 5.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BD1A13B3389E85C15EA5A6F0783580E6
.pdata 0x00900000 286,404 bytes 286,720 bytes 6.55 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1E61EB98D7773B0326CB4C9B81BFE6C9
.rsrc 0x00946000 207,368 bytes 207,872 bytes 7.90 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7797768FFD450DB0D8B22C3F5377673B
.reloc 0x00979000 30,132 bytes 30,208 bytes 5.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 79BFDE4C103A44273CACCFA92F855352
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 8 (206,878 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 206,237 bytes
99.7%
RT_GROUP_ICON 1 90 bytes
0%
RT_MANIFEST 1 551 bytes
0.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware