File Name | Ghostpress.exe |
File Type |
Win32 EXE
|
Magic Bytes | PE32 executable (GUI) Intel 80386, for MS Windows |
SSDEEP Hash |
196608:mmfPQQaR0b9Yi3BKy9ZRQh20u1xHFab/a:JPQha6i3Y8Q3u1xw7
|
Scanner Version | 1.0.185.174 |
Database Version | 2024-08-19 13:00:13 UTC |
Detected by 19 security engines - requires caution
Hash Type | Value | Action |
---|---|---|
MD5 |
760ed01578186a6d7d5044615671c0cc
|
|
SHA1 |
9dab87a25f704b099ffde12f14c74cbc074de70f
|
|
SHA256 |
567a402cc4ea063393d86fbabf6268892fbbb34337de818f5576acd0cfcfb260
|
|
SHA512 |
03d0f3c2032294936d88248d1036cd9c6493a952825528f41d9429c3bd899d111ee21c84c9b595745150280c492691681c1be355f1418573305028779646c18d
|
|
ImpHash |
4328f7206db519cd4e82283211d98e83
|
Icon |
Hash: a90f38273de2f539ee35592805ba79f9
Fuzzy: 4232b125c4afb4a62df2816704ec0f61 dHash: 3271d496c0d49669 |
Image Base | 0x00400000 |
Entry Point | 0x00e94058 |
Compilation Time | 1970-01-01 00:00:00 |
Checksum | 0x0072cf38 (Actual: 0x0072cf38) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports |
2 libraries
kernel32, mscoree |
Exports | 0 functions |
Resources | 4 Resources |
Sections | 7 Sections |
Translation | 0x0000 0x04b0 |
Comments | |
CompanyName | schiffer.tech UG (haftungsbeschränkt) |
FileDescription | Ghostpress |
FileVersion | 2.6.1352 |
InternalName | Ghostpress.exe |
LegalCopyright | Copyright © schiffer.tech UG (haftungsbeschränkt) 2015-2024 |
LegalTrademarks | |
OriginalFilename | Ghostpress.exe |
ProductName | Ghostpress |
ProductVersion | 2.6.1352 |
Assembly Version | 2.6.1352.0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
|
0x00002000 |
999,424 bytes | 484,864 bytes | 7.98 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
2A138D9DBE1213817B8B453B0B66BED0 |
|
0x000f6000 |
13,218 bytes | 12,288 bytes | 7.84 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
67C7D9EA4C061519E5DF0C46D6CCCBF5 |
|
0x000fa000 |
12 bytes | 512 bytes | 0.24 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
7D037DF7F5AEAB881F7FA99339E228A8 |
.idata |
0x000fc000 |
8,192 bytes | 512 bytes | 1.15 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
4C96D2A19F554ECBF0F84F04A7D2CB3B |
.rsrc |
0x000fe000 |
13,312 bytes | 13,312 bytes | 7.51 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
AC5FD5D3A8A15B3481CB0B9CF4886ECE |
schiffer |
0x00102000 |
10,035,200 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.boot |
0x00a94000 |
6,949,376 bytes | 6,949,376 bytes | 7.95 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
F2CEDD66C0C86523587CCCC3BF2F8DFE |
4 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 1 | 9,544 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_VERSION | 1 | 982 bytes | |
RT_MANIFEST | 1 | 2,366 bytes |
Product | Ghostpress |
Description | Ghostpress |
File Version | 2.6.1352 |
Original Name | Ghostpress.exe |
Signing Date | 06:31 PM 06/04/2024 (373 days ago) |
Verification Status | Signed |
Signers | schiffer.tech UG (haftungsbeschränkt); Certum Code Signing 2021 CA; Certum Trusted Network CA 2 |
Counter Signers | Sectigo RSA Time Stamping Signer #4; Sectigo RSA Time Stamping CA; Sectigo |
Internal Name | Ghostpress.exe |
Copyright | Copyright © schiffer.tech UG (haftungsbeschränkt) 2015-2024 |
99 A3 80 0A 26 55 3B 65 AB DC 6E 84 A6 B3 EA 39
30 0F 6F AC DD 66 98 74 7C A9 46 36 A7 78 2D B9
39 4C 25 E1 7C A0 6D 27 A8 65 E2 3B D9 1D 22 D4
71 FB 97 D5 DF EE FB 1B 9D D4 91 FB 72 C0 F0 DC
7B 05 B1 D4 49 68 51 44 F7 C9 89 D2 9C 19 9D 12
7B D4 E5 AF BA CC 07 3F A1 01 23 04 22 41 4D 12
✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important