Gridinsoft Logo

The 4fce9a2c6aae351e27c2b6fc104c30597f293a455413dd7008bdf446b9657b0d File Analysis

Technical Analysis

File Name 4fce9a2c6aae351e27c2b6fc104c30597f293a455413dd7008bdf446b9657b0d
File Type
Win32 EXE
Magic Bytes PE32 executable (console) Intel 80386, for MS Windows
SSDEEP Hash
24576:jZtdEBlJK7hlKGgwSTm36mZMehMFYLXPFKaFC9XxggS7wPPZteuY7PW/hZ:jZtdX7hl3SfeaeIaF25SEZcuY7PW/hZ
Scanner Version 1.0.139.174
Database Version 2023-09-16 23:00:58 UTC

Suspicious File Detected

Detected by 31 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
44%
Detection Rate
1,461,248
File Size (bytes)
31/71
Engines Detected
2023-09-16
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0a7291a4760b7f8afc682186aa0a4666
SHA1
af58faaa10c572e1ed3a5c91d89524a7be211627
SHA256
4fce9a2c6aae351e27c2b6fc104c30597f293a455413dd7008bdf446b9657b0d
SHA512
eece94c45fec0fbe0b0377d26e6f93639eea91a4b360e7c8ddedd0a0ea63df90579a1bbbc30f60f69164b367ff5e9f783b383d3aacc8d89803aaff7ab404db8d
ImpHash
fc6316c96fc105fcdafe08845aa690ab

Security Engines with Detections (31 of 71)

Bkav
W32.AIDetectMalware Malicious
Elastic
malicious (high confidence) Malicious
MicroWorld-eScan
Gen:Variant.Jaik.151283 Malicious
ALYac
Gen:Variant.Jaik.151283 Malicious
VIPRE
Gen:Variant.Jaik.151283 Malicious
Sangfor
Trojan.Win32.Save.a Malicious
Cybereason
malicious.a10c57 Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of Win32/Kryptik.HTQR Malicious
APEX
Malicious Malicious
Cynet
Malicious (score: 100) Malicious
Kaspersky
HEUR:Trojan-PSW.Win32.Stealerc.gen Malicious
BitDefender
Gen:Variant.Jaik.151283 Malicious
Avast
Win32:PWSX-gen [Trj] Malicious
Emsisoft
Gen:Variant.Jaik.151283 (B) Malicious
DrWeb
Trojan.Siggen21.29673 Malicious
McAfee-GW-Edition
BehavesLike.Win32.Generic.tc Malicious
FireEye
Generic.mg.0a7291a4760b7f8a Malicious
SentinelOne
Static AI - Suspicious PE Malicious
GData
Gen:Variant.Jaik.151283 Malicious
MAX
malware (ai score=89) Malicious
Arcabit
Trojan.Jaik.D24EF3 Malicious
ZoneAlarm
HEUR:Trojan-PSW.Win32.Stealerc.gen Malicious
Microsoft
Trojan:Script/Phonzy.B!ml Malicious
Panda
Trj/Genetic.gen Malicious
Rising
[email protected] (RDML:ycAAjtsYXhdaF2JhIIsxSg) Malicious
MaxSecure
Trojan.Malware.300983.susgen Malicious
BitDefenderTheta
Gen:NN.ZexaF.36662.zvW@aW3np@c Malicious
AVG
Win32:PWSX-gen [Trj] Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/malicious_confidence_70% (D) Malicious
40 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x00409a7d
Compilation Time 2023-09-16 20:43:41
Checksum 0x00000000 (Actual: 0x001684e1)
OS Version 6.0
PEiD Signatures PE32 executable (console) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 1 libraries
KERNEL32
Exports 1 functions
Resources 0 Resources
Sections 5 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 154,810 bytes 155,136 bytes 6.67 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 56459A75E357BBD0CCB1936EEF090CEA
.rdata 0x00027000 55,296 bytes 55,296 bytes 5.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 308430E079F12295C02621BC2EA341FD
.data 0x00035000 7,756 bytes 4,096 bytes 2.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8638AEBBB77A3BB624A1997A9775C139
.bss 0x00037000 1,237,804 bytes 1,238,016 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7871D831214322A2AE6F7E3C0D0DDA3F
.reloc 0x00166000 7,200 bytes 7,680 bytes 6.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 85C316EFBFA820730E7D27DCAD8ABD17
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
31 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware