The build.exe File Analysis
Technical Analysis
| File Name | build.exe |
| File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| Scanner Version | 1.0.214.174 |
| Database Version | 2025-04-15 23:00:14 UTC |
Clean File
No threats detected by our scanner
Scan Another File
File Identification
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
134025ff5dd92ba6a89686e5c91dd7c7
|
|
| SHA1 |
15c226f202f5c413a521f0e9f4d95df7a603ca6a
|
|
| SHA256 |
6b949d68552bf82846ab3852277ddd5ec4d45099a3c9cf5b903a7d2e89b9972a
|
|
| SHA512 |
be5c6d20c14e64144d220874201f491ade44c501b290734180eb6dd74387150f3b20cea7e47b1958fcfdfa3d34524ffa50f7e2b89396e04668d35cdb1ae42402
|
|
| ImpHash |
038039cd1b98203d53cfced3d6fa2ad8
|
PE Analysis
Basic Information
▼| Icon |
Hash: d46377a82ec5b7e5a461ee03661128a8
Fuzzy: 2ee8976d2269ce775b082ba351084b67 dHash: 94b4e8e8c2ba9d40 |
| Image Base | 0x00400000 |
| Entry Point | 0x004014c0 |
| Compilation Time | 2015-02-03 15:09:20 |
| Checksum | 0x00106497 (Actual: 0x00106497) |
| OS Version | 4.0 |
| PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| Digital Signature | No valid SignedData structure was found. |
| Imports |
7 libraries
COMCTL32, GDI32, KERNEL32, msvcrt, libwinpthread-1, SHELL32, USER32 |
| Exports | 0 functions |
| Resources | 6 Resources |
| Sections | 17 Sections |
PE Sections
▼| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
520,248 bytes | 520,704 bytes | 6.47 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_16BYTES
|
DA3EAA6CC6B0406F59C6B4020E190A6C |
.data |
0x00081000 |
32,076 bytes | 32,256 bytes | 1.86 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES
|
71ADF513F6B709B39025726DDD3F5EA6 |
.rdata |
0x00089000 |
62,024 bytes | 62,464 bytes | 6.36 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES
|
2F7F7837F17AFE4F253C3396E0018417 |
/4 |
0x00099000 |
42,068 bytes | 42,496 bytes | 4.99 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES
|
B261AFBB224272D2433A28E2375457A9 |
.bss |
0x000a4000 |
4,889,248 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x0054e000 |
5,800 bytes | 6,144 bytes | 5.24 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
3C9641C8A5051F776AB3179ED7D5A904 |
.CRT |
0x00550000 |
52 bytes | 512 bytes | 0.28 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
F62BB698BCF1021E67A0747BCAF8B180 |
.tls |
0x00551000 |
32 bytes | 512 bytes | 0.21 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
8256CC33ED6A1979DD6417A2BEDC0D64 |
.rsrc |
0x00552000 |
30,984 bytes | 31,232 bytes | 5.73 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
43C55D83C49AE345A312678FD7B87EE6 |
/14 |
0x0055a000 |
184 bytes | 512 bytes | 0.91 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_8BYTES
|
95A5873D39E7130A020E5710C49A0AA6 |
/29 |
0x0055b000 |
46,179 bytes | 46,592 bytes | 6.01 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
2EA315C8078CAF367B5D6983806872FD |
/41 |
0x00567000 |
4,073 bytes | 4,096 bytes | 4.77 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
3F25D065BFF3F64EB283E78AAA581E65 |
/55 |
0x00568000 |
6,383 bytes | 6,656 bytes | 6.24 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
E457E598E3A3B7DE302F70C8D43480FB |
/67 |
0x0056a000 |
56 bytes | 512 bytes | 0.68 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES
|
C30C6844E27398EC7A8942D7BD72FEE0 |
/80 |
0x0056b000 |
287 bytes | 512 bytes | 3.09 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
80DEB218701DBB08439EA33BD723A6B0 |
/91 |
0x0056c000 |
35,482 bytes | 35,840 bytes | 4.23 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
5D6A5E06A61DF6E08B1AABD3AA488AB5 |
/102 |
0x00575000 |
3,304 bytes | 3,584 bytes | 3.31 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
3AC31E56468BFB8921B5BA028E2062E2 |
Resource Analysis
▼| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| RT_BITMAP | 1 | 26,760 bytes | |
| RT_ICON | 2 | 2,960 bytes | |
| RT_DIALOG | 2 | 826 bytes | |
| RT_GROUP_ICON | 1 | 34 bytes |
Certificate Chain Analysis
▼No Digital Signatures
This file is not digitally signed.
Security Implications:
- Cannot verify the publisher's identity
- Increased security risk when running this file
- May trigger security warnings on some systems
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
Certificate Verification Status
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Remember: This is Result of Online Virus Scanner
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-Malware
Keep Your System Protected
This file appears clean, but regular security maintenance is important
-
1
Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
-
2
Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
-
3
Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
-
4
Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Leave a Comment
Gridinsoft Anti-Malware
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!