Gridinsoft Logo

The curl.exe (The curl executable) File Analysis

Technical Analysis

File Name curl.exe
File Type
PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-07 02:00:38 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,640,728
File Size (bytes)
2025-03-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
971e9cc95aaca3e0537a8633dad89c4a
SHA1
367837151ad10f31084d6833a196edc3e36d4c61
SHA256
52f7627a29863beed3d24855f05245b90acbc13df035cc7419e408e6690564c5
SHA512
d2e390d6ccf160af18e76f236716787d8459f976ba3eaeb7c267ec748810612e036a27660fbc41d8b9e5b7ef4d4ca0d97dccc38c9e2978fbee53219e24737025
ImpHash
4c1eeec43423f934059f8bee4054391d

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004014a0
Compilation Time 2019-07-19 09:38:04
Checksum 0x0037d05c (Actual: 0x0037d05c)
OS Version 4.0
PEiD Signatures PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
Digital Signature OK
Imports 8 libraries
ADVAPI32, CRYPT32, KERNEL32, msvcrt, Normaliz, USER32, wldap32, WS2_32
Exports 0 functions
Resources 2 Resources
Sections 10 Sections

Version Information

CompanyName curl, https://curl.haxx.se/
FileDescription The curl executable
FileVersion 7.65.3
InternalName curl
OriginalFilename curl.exe
ProductName The curl executable
ProductVersion 7.65.3
LegalCopyright © 1996 - 2019 Daniel Stenberg, <[email protected]>.
License https://curl.haxx.se/docs/copyright.html
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,730,340 bytes 2,732,032 bytes 6.36 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4096BYTES 0707697E3221E5810DF0AA7278139EA0
.data 0x0029c000 15,644 bytes 15,872 bytes 3.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES F45E4B354FEC3C351780242A0F659003
.rdata 0x002a0000 773,056 bytes 773,120 bytes 6.51 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES AEAD6023939109F3E73D8F890C449014
.bss 0x0035d000 14,912 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES D41D8CD98F00B204E9800998ECF8427E
.edata 0x00361000 49 bytes 512 bytes 0.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 4DFF8FE7B8F3912916172FC0C9BA8EBA
.idata 0x00362000 7,884 bytes 8,192 bytes 5.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES BF24DEF502FBACE228A71A30EB610CC4
.CRT 0x00364000 52 bytes 512 bytes 0.28 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES 4A6173E3A1F708287960808FFF1BC8EA
.tls 0x00365000 8 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x00366000 1,880 bytes 2,048 bytes 4.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES 0D9E38223467A20C7169356CA91145AA
.reloc 0x00367000 97,716 bytes 97,792 bytes 6.57 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 6D583240C450C2DED00B24CB826E0A2D
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 2 (1,713 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 908 bytes
53%
RT_MANIFEST 1 805 bytes
47%

Certificate Chain Analysis

Certificate Information
Product The curl executable
Description The curl executable
File Version 7.65.3
Original Name curl.exe
Signing Date 08:24 AM 08/26/2019 (2112 days ago)
Verification Status Signed
Signers Greatis Software LLC; Symantec Class 3 SHA256 Code Signing CA; VeriSign
Counter Signers Symantec Time Stamping Services Signer - G4; Symantec Time Stamping Services CA - G2; Thawte Timestamping CA
Internal Name curl
Copyright © 1996 - 2019 Daniel Stenberg, <[email protected]>.
Certificate Chain Summary
Symantec Time Stamping Services CA - G2 #1 Primary
Validity Period: 2012-12-21 00:00:00 → 2020-12-30 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
Symantec Time Stamping Services Signer - G4 #2 Chain
Validity Period: 2012-10-18 00:00:00 → 2020-12-29 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
Greatis Software LLC #3 Chain
Validity Period: 2016-11-08 00:00:00 → 2019-12-08 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 68 47 21 E6 FE 26 27 77 5D FC 2A 71 7E 65 F3 F2
Symantec Class 3 SHA256 Code Signing CA #4 Chain
Validity Period: 2013-12-10 00:00:00 → 2023-12-09 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 3D 78 D7 F9 76 49 60 B2 61 7D F4 F0 1E CA 86 2A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware