Gridinsoft Logo
File Icon

The exe.win-amd64-3.12.exe File Analysis

Technical Analysis

File Name exe.win-amd64-3.12.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.178.174
Database Version 2024-05-29 10:00:19 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
9,725,275
File Size (bytes)
2024-05-29
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6fadba46e892c5a49d044266a8ff6fd5
SHA1
ab1fec405ad7bd0dfeeb47fc2d45b1f07dd2550d
SHA256
71d6e5f74cd4bcc0c87da86e3ed791ab57e80eb43a91791fc8419ee6c32cbf54
SHA512
1f8cee2c92de332794cba49b2b77509fbcaef3851c56325d9263b5f77c9e0451e0ddf16a28aed5cad889c76bce88363c50016f7d862114d37ec35fe574e98139
ImpHash
b1c5b1beabd90d9fdabd1df0779ea832

PE Analysis

Basic Information

Icon
Hash: 8d9da329386d64d6b86a12bd2f986399
Fuzzy: 9043363bfee17e0d508057b9ae7189e9
dHash: 84b4b4d4c4ccccc0
Image Base 0x140000000
Entry Point 0x140032ee0
Compilation Time 2024-05-12 10:17:07
Checksum 0x00000000 (Actual: 0x0094c2be)
OS Version 5.2
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 3 libraries
KERNEL32, OLEAUT32, gdiplus
Exports 0 functions
Resources 28 Resources
Sections 8 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 288,622 bytes 288,768 bytes 6.47 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ F06BB06E02377AE8B223122E53BE35C2
.rdata 0x00048000 75,972 bytes 76,288 bytes 5.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 2DE06D4A6920A6911E64FF20000EA72F
.data 0x0005b000 59,228 bytes 6,656 bytes 3.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0DBDB901A7D477980097E42E511A94FB
.pdata 0x0006a000 12,396 bytes 12,800 bytes 5.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B0CE0F057741AD2A4EF4717079FA34E9
.didat 0x0006e000 864 bytes 1,024 bytes 3.05 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1FCC7B1D7A02443319F8FCC2BE4CA936
_RDATA 0x0006f000 348 bytes 512 bytes 3.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3F331EC50F09BA861BEAF955B33712D5
.rsrc 0x00070000 58,208 bytes 58,368 bytes 6.60 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ ADA5628B9441C3D4F775B5C1BE0267EF
.reloc 0x0007f000 2,416 bytes 2,560 bytes 5.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 77A9DDFC47A5650D6EEBBCC823E39532
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 28 (56,468 bytes)
Resource Type Count Total Size Percentage
PNG 2 8,430 bytes
14.9%
RT_ICON 7 38,113 bytes
67.5%
RT_DIALOG 6 2,916 bytes
5.2%
RT_STRING 11 5,030 bytes
8.9%
RT_GROUP_ICON 1 104 bytes
0.2%
RT_MANIFEST 1 1,875 bytes
3.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
This file looks clean right now, but that doesn't mean you should let your guard down. New malware appears daily, and even legit files can be compromised after download. When in doubt, verify the source and check for a digital signature.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware