Gridinsoft Logo
File Icon

The EXE64.exe (Executable File Explorer for OS/2, NE, PE32, PE32+ and VxD file types) File Analysis

Technical Analysis

File Name EXE64.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-18 19:00:32 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
7,299,384
File Size (bytes)
2025-03-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
28652f9efa6e5a46c2add5aa685c48e9
SHA1
cc1b64b8025bc195612eaf2089176d940118c681
SHA256
60e9280133afe2ae06424478406521b34b10254048a704970383b1221392d325
SHA512
e3bc3696f247d8aa0d24b1527a67134e8f8aacf5fccf08cf5fb2fe6f26a479edcca4f7c59f2c447cbbd01e5f1940e3e23282f032f8b889cc97bb142870b3de45
ImpHash
7e54fe22dcf220f91086592373473d09

PE Analysis

Basic Information

Icon
Hash: 55bfe666672f98b046359c34c2599b71
Fuzzy: 13d7fe34a36fcf5dc8f55715e3442849
dHash: 0321c0c4e4048225
Image Base 0x00400000
Entry Point 0x0162a438
Compilation Time 2024-12-17 07:33:19
Checksum 0x006fbc01 (Actual: 0x006fbc01)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature OK
Imports 4 libraries
advapi32, kernel32, shell32, user32
Exports 0 functions
Resources 201 Resources
Sections 11 Sections

Version Information

CompanyName MiTeC
FileDescription Executable File Explorer for OS/2, NE, PE32, PE32+ and VxD file types
FileVersion 3.7.4.0
LegalCopyright Copyright (c) 2006-2024, Michal Mutl
LegalTrademarks All rights reserved
ProductName EXE Explorer
ProductVersion 3.0.0.0
OriginalFilename EXE64.exe
BuildTimestamp 2024-12-17 08:33:19
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 10,662,340 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
0x00a2d000 906,128 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00b0b000 82,388 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00b20000 25,812 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00b27000 6,128 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00b29000 108 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
0x00b2a000 656 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00b2b000 109 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.reloc 0x00b2c000 470,384 bytes 470,528 bytes 6.50 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ F9B456A926900092B13E278A923B068E
.rsrc 0x00b9f000 6,860,788 bytes 2,368,512 bytes 7.93 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 93320BE818FA7FBC8DDB4464C5565987
0x0122a000 358,288 bytes 358,400 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7EF739D848C008E46C97C19CC45E7824
Entropy Analysis Alert

2 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 201 (6,848,129 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 16 8,448 bytes
0.1%
RT_BITMAP 30 17,344 bytes
0.3%
RT_ICON 5 34,408 bytes
0.5%
RT_STRING 63 56,560 bytes
0.8%
RT_RCDATA 68 6,728,234 bytes
98.2%
RT_GROUP_CURSOR 16 320 bytes
0%
RT_GROUP_ICON 1 76 bytes
0%
RT_VERSION 1 936 bytes
0%
RT_MANIFEST 1 1,803 bytes
0%

Certificate Chain Analysis

Certificate Information
Product EXE Explorer
Description Executable File Explorer for OS/2, NE, PE32, PE32+ and VxD file types
File Version 3.7.4.0
Original Name EXE64.exe
Signing Date 07:33 AM 12/17/2024 (172 days ago)
Verification Status Signed
Signers ing. Michal Mutl; Sectigo Public Code Signing CA R36; Sectigo Public Code Signing Root R46; Sectigo (AAA)
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Copyright Copyright (c) 2006-2024, Michal Mutl
Certificate Chain Summary
Sectigo Public Code Signing Root R46 #1 Primary
Validity Period: 2021-05-25 00:00:00 → 2028-12-31 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
Sectigo Public Code Signing CA R36 #2 Chain
Validity Period: 2021-03-22 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 62 1D 6D 0C 52 01 9E 3B 90 79 15 20 89 21 1C 0A
ing. Michal Mutl #3 Chain
Validity Period: 2022-02-21 00:00:00 → 2025-02-20 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 7F B2 DC 3C 0F 1D 43 E1 D1 FE 62 5E 05 5C 14 80
DigiCert Timestamp 2024 #4 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #5 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #6 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware