Gridinsoft Logo

The Installer.exe (Installer) File Analysis

Technical Analysis

File Name Installer.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.220.174
Database Version 2025-07-13 16:00:20 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
19,603,101
File Size (bytes)
2025-07-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
f0dbd11290d6352414cd8968bb2bd183
SHA1
802bdff5e8e7f5a6b3233c7faaf853a97559148b
SHA256
6c208cb5f3bc408a6106c0e5a555947e54e8a606de0bacc7634b9d1917259950
SHA512
4771c83c102fb7e86a84b52f9622b9dfd7cf9c345c606f8e1b0a48d96b1eb68aaeee0f9b4ebe6613c78f9b5d759a7d6e4beac6798cc6e1348e7d9ce66f7a839a
ImpHash
404f8881ca54c321b75ad15072248e8e

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1405efd80
Compilation Time 2025-02-11 23:10:37
Checksum 0x00000000 (Actual: 0x012bb2c3)
OS Version 6.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
PDB Path D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
Digital Signature No valid SignedData structure was found.
Imports 17 libraries
Exports 6 functions
Resources 5 Resources
Sections 9 Sections

Version Information

Translation 0x0000 0x04b0
CompanyName Sebastien Lebreton
FileDescription Installer
FileVersion 3.2.0.0
InternalName Installer.dll
LegalCopyright Sebastien Lebreton
OriginalFilename Installer.dll
ProductName Installer
ProductVersion 3.2.0.0+60881bae6fcb680ec70a0d6249b85531ce7709c8
Assembly Version 3.2.0.0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,597,132 bytes 6,597,632 bytes 6.45 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9B4B2829F78749D464C4D81FEDA4CE71
.CLR_UEF 0x0064c000 215 bytes 512 bytes 3.07 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C569176CF9F2427FCFCD45267E526B2A
.rdata 0x0064d000 1,600,262 bytes 1,600,512 bytes 5.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 53836719B79F0BF7A3919137C3F7A820
.data 0x007d4000 107,144 bytes 24,576 bytes 2.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 05C13DECDA8E25EA99082658320D84CD
.pdata 0x007ef000 231,492 bytes 231,936 bytes 6.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0840536909B9EB1EE4C2BD4E2803C74E
.didat 0x00828000 56 bytes 512 bytes 0.42 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 48032D4C0F884C2B3960A8BA2A3E65AB
Section 0x00829000 8 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0082a000 1,360,780 bytes 1,360,896 bytes 6.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C5ED9FFC1FAD6A08337224D7D361F7F1
.reloc 0x00977000 31,648 bytes 31,744 bytes 5.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8DD78D45F1A853077B1B6522E4B26642

Resource Analysis

Total Resources: 5 (1,360,298 bytes)
Resource Type Count Total Size Percentage
RT_RCDATA 3 1,358,960 bytes
99.9%
RT_VERSION 1 848 bytes
0.1%
RT_MANIFEST 1 490 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Installer
Description Installer
File Version 3.2.0.0
Original Name Installer.dll
Internal Name Installer.dll
Copyright Sebastien Lebreton
Certificate Chain Summary
.NET DAC #1 Primary
Validity Period: 2024-10-10 20:21:25 → 2025-07-04 20:21:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 05 B3 02 17 FC 2A 4C 56 98 3B 00 00 00 00 05 B3
Microsoft Code Signing PCA 2010 #2 Chain
Validity Period: 2010-07-06 20:40:17 → 2025-07-06 20:50:17
Signature Algorithm: sha256RSA
Serial Number: 61 0C 52 4C 00 00 00 00 00 03
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2024-07-25 18:31:22 → 2025-10-22 18:31:22
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 01 D1 45 59 98 10 CC 42 4F 00 01 00 00 02 01
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware