Gridinsoft Logo
File Icon

The JDownloader_40044.exe (JDownloader Install: Peace Team) File Analysis

Technical Analysis

File Name JDownloader_40044.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
786432:dXsGTwx8LRNA4S+Xn9rvMQFaFxFi6YRhjePrPn:OQX+Y9wyibMRlab
Scanner Version 1.0.215.174
Database Version 2025-04-26 16:00:20 UTC

Suspicious File Detected

Detected by 5 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
7%
Detection Rate
29,573,008
File Size (bytes)
5/72
Engines Detected
2025-04-26
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
49ae29e9aada5ce35ffd1b77727cdede
SHA1
c46d6f47dbf749dc2a3600d9ed1a06acef83f1be
SHA256
724a886bf3f611f46858c9162c7666af57d748aa6b828b544b7f58ac0839113e
SHA512
75ba9c07315149ca14e674751094b2fb4791888f8b762415b1abe6ab63cf3060b8792ac21cd33d40b58a3b019e9cb593f34195187ef83f3653d84d993846c6b6
ImpHash
fc01d47b443e3a2cf2d159f5ba1e8aba

Security Engines with Detections (5 of 72)

ESET-NOD32
a variant of Win32/Adware.OpenSUpdater.LC.gen Malicious
NANO-Antivirus
Riskware.Win32.OpenSUpdater.kwusjq Malicious
DrWeb
Adware.Downware.20675 Malicious
McAfeeD
ti!724A886BF3F6 Malicious
Malwarebytes
Adware.SpecialSearchOffer Malicious
67 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: e70ab6434b901bf0d86cad4f2e381b4b
Fuzzy: c0aeeb48c2783a270a993faae44e6ec1
dHash: 00b28eabababa600
Image Base 0x00400000
Entry Point 0x0054eaaa
Compilation Time 2024-11-22 07:03:41
Checksum 0x01c3ffb2 (Actual: 0x01c3ffb2)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 9 libraries
KERNEL32, USER32, ADVAPI32, SHELL32, ole32, OLEAUT32, WS2_32, CRYPT32, WLDAP32
Exports 0 functions
Resources 25 Resources
Sections 5 Sections

Version Information

CompanyName Peace Team
FileDescription JDownloader Install: Peace Team
FileVersion 1.0.0.1
ProductVersion 1.0.0.1
LegalCopyright Copyright 2010-2024 Peace Team
ProductName JDownloader Install: Peace Team
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,786,204 bytes 1,786,368 bytes 6.26 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5882847006F6EEC88585E660DEE9A7FB
.rdata 0x001b6000 127,302 bytes 127,488 bytes 5.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 062E4D8E5CF2E95AAB78EC3552141F84
.data 0x001d6000 36,076 bytes 10,240 bytes 4.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9E6AB4E0C5BB148CFE487CDB745118E9
.rsrc 0x001df000 9,496 bytes 9,728 bytes 3.82 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DA6E92DA11C57D10C7E42E83062D21B8
.reloc 0x001e2000 46,202 bytes 46,592 bytes 5.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ FDB042834A386157F0818EEDB160A7EB

Resource Analysis

Total Resources: 25 (8,066 bytes)
Resource Type Count Total Size Percentage
RT_ICON 2 1,040 bytes
12.9%
RT_DIALOG 4 2,048 bytes
25.4%
RT_STRING 16 2,766 bytes
34.3%
RT_GROUP_ICON 1 34 bytes
0.4%
RT_VERSION 1 676 bytes
8.4%
RT_MANIFEST 1 1,502 bytes
18.6%

Certificate Chain Analysis

Certificate Information
Product JDownloader Install: Peace Team
Description JDownloader Install: Peace Team
File Version 1.0.0.1
Signing Date 07:25 AM 11/22/2024 (204 days ago)
Verification Status Signed
Signers ZIPLINE TECH, LLC; GlobalSign GCC R45 EV CodeSigning CA 2020; GlobalSign Code Signing Root R45
Counter Signers Globalsign TSA for CodeSign1 - R6 - 202311; GlobalSign Timestamping CA - SHA384 - G4; GlobalSign Root CA - R6
Copyright Copyright 2010-2024 Peace Team
Certificate Chain Summary
GlobalSign GCC R45 EV CodeSigning CA 2020 #1 Primary
Validity Period: 2020-07-28 00:00:00 → 2030-07-28 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 77 BD 0E 05 B7 59 0B B6 1D 47 61 53 1E 3F 75 ED
ZIPLINE TECH, LLC #2 Chain
Validity Period: 2024-07-30 18:20:57 → 2025-07-31 18:20:57
Signature Algorithm: sha256RSA
Serial Number: 5E FE A8 7F C8 DC 1A 52 69 0B 79 5A
Globalsign TSA for CodeSign1 - R6 - 202311 #3 Chain
Validity Period: 2023-11-07 17:13:40 → 2034-12-09 17:13:40
Signature Algorithm: sha256RSA
Serial Number: 01 9B EA DE C8 4D 6B 8F F7 6C 3A 9F 2E 01 24 16
GlobalSign Timestamping CA - SHA384 - G4 #4 Chain
Validity Period: 2018-06-20 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 01 EC 1C 92 40 DE FD 2E 40 5D 7C 47 74
GlobalSign #5 Chain
Validity Period: 2014-12-10 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 45 E6 BB 03 83 33 C3 85 65 48 E6 FF 45 51

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
5 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware