Gridinsoft Logo

The libcares-2.dll (Ջերմուկ) File Analysis

Technical Analysis

File Name libcares-2.dll
File Type
Win32 DLL
Magic Bytes PE32+ executable (DLL) (GUI) x86-64, for MS Windows
SSDEEP Hash
49152:umzIvlMH+3kH8T9E0tiqZaB831sloW9s5PA2lJ3S:3k2gn
Scanner Version 1.0.215.174
Database Version 2025-04-27 17:00:20 UTC

Suspicious File Detected

Detected by 8 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
11%
Detection Rate
2,599,424
File Size (bytes)
8/72
Engines Detected
2025-04-27
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
bcd4f6c7dd570c9f84dcbae29d8fcb22
SHA1
b2bd862459463c66ab7c2fdd848063b9b68733bd
SHA256
69133b4f946596da0db8e3b80fca1a428fa1cb88abba988609f864172b414d35
SHA512
f81a21029e9a363600c8a63408c151ad9d5f7ef11f9eb3da143e89f79a9ad3f80b2db7527c2484070cdad2be9efb733da811156af2c8a83a1a19e94ee54347ff
ImpHash
06c7b3ff6f53325203a75ffe8135b7de

Security Engines with Detections (8 of 72)

Elastic
malicious (moderate confidence) Malicious
huorong
Trojan/MSIL.Injector.po Malicious
ESET-NOD32
a variant of Win64/Agent.ECK Malicious
Google
Detected Malicious
Ikarus
Trojan.Win64.Agent Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
Cynet
Malicious (score: 100) Malicious
Fortinet
W64/GenKryptik.HFPH!tr Malicious
64 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x18018115c
Compilation Time 2025-04-25 01:13:14
Checksum 0x00000000 (Actual: 0x00281e5f)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
PDB Path C:\Windows\Microsoft.Meefd589e#\Microsoft.B22c61a69#\TxR\Microsoft.C8d726d22#\WTR\hh.pdb
Digital Signature No valid SignedData structure was found.
Imports 10 libraries
ADVAPI32, bcrypt, KERNEL32, ole32, api-ms-win-crt-math-l1-1-0, api-ms-win-crt-heap-l1-1-0, api-ms-win-crt-string-l1-1-0, api-ms-win-crt-convert-l1-1-0, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-stdio-l1-1-0
Exports 322 functions
Resources 1 Resources
Sections 7 Sections

Version Information

Translation 0x0000 0x04b0
Comments Գյումրի Տվյալների Վերլուծիչ մեծածավալ ինֆորմացիայի միավորման և վերլուծության համար
CompanyName Կովկաս Տեխնոլոգիական Լուծումներ
FileDescription Ջերմուկ
FileVersion 221.210.9135.0246
InternalName Ջերմուկ.dll
LegalCopyright
OriginalFilename Ջերմուկ.dll
ProductName Գյումրի Տվյալների Վերլուծիչ
ProductVersion 1.0.0
Assembly Version 221.210.9135.246

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,596,456 bytes 1,596,928 bytes 6.56 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5A835A523C899870B244DD829A49C565
.rdata 0x00187000 886,728 bytes 886,784 bytes 6.78 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8BAEDE4CA016B15B5852C2474BFACDA3
.data 0x00260000 535,056 bytes 9,216 bytes 3.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2C188C2DEE3B77FCE933050B75357B5C
.pdata 0x002e3000 101,112 bytes 101,376 bytes 6.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 687B8394A387AD210AE57884D99A96D7
_RDATA 0x002fc000 348 bytes 512 bytes 3.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C8EFE6627BF72F08AEDE43DEFCF04744
.rsrc 0x002fd000 1,090 bytes 1,536 bytes 3.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 16089541D8A0A02CDBED5B49441BD9BC
.reloc 0x002fe000 1,836 bytes 2,048 bytes 5.05 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8C9410C3056F99BA6E880EA8C0847644
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 1 (1,002 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 1,002 bytes
100%

Certificate Chain Analysis

Certificate Information
Product Գյումրի Տվյալների Վերլուծիչ
Description Ջերմուկ
File Version 221.210.9135.0246
Original Name Ջերմուկ.dll
Internal Name Ջերմուկ.dll

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
8 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware