Gridinsoft Logo
File Icon

The tenorshare-4ddig-for-windows.exe (Tenorshare 4DDiG) File Analysis

Technical Analysis

File Name tenorshare-4ddig-for-windows.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
SSDEEP Hash
49152:S1OOKgkBsWP5UXpv4k6rKRUCoyUzY2U9JssMOQCfv9iXJE8pVkpxwGy1L9J2:S1ZNKe54k6aUCoyU024JssoCfv9cBpVe
Scanner Version 1.0.184.174
Database Version 2024-08-14 20:00:25 UTC

Suspicious File Detected

Detected by 6 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
8%
Detection Rate
2,446,096
File Size (bytes)
6/74
Engines Detected
2024-08-14
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a588b69851b6fb540674d6baaa49932f
SHA1
180532dce3d8f2fc18010ec3974663dd23defcd7
SHA256
7334f20e6ff246713cd7ba26882b45cc6dc4d13097a902fb72ed2f0dab5482f6
SHA512
2d47616e7b2d909fd3924787498c2dda343bc524dee1c4fe29417d54fe1e8e283f640870a6ca48122e445bf91946c91f647a972e92699d6fb48f1d7f8578a1e8
ImpHash
fe5fb373dbec3ba73ffb51335d1fc086

Security Engines with Detections (6 of 74)

Cylance
Unsafe Malicious
Paloalto
generic.ml Malicious
Antiy-AVL
Trojan/Win32.Agent Malicious
Xcitium
ApplicUnwnt@#fma0istd1uqc Malicious
Malwarebytes
PUP.Optional.4DDIG Malicious
Fortinet
W32/PossibleThreat Malicious
68 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: d5d4ded703091e6e74135477a467e1e0
Fuzzy: 788a9cfc8ce0fcc4f2f687787f8fa582
dHash: b2498f930b0c0fb2
Image Base 0x00400000
Entry Point 0x0082cd40
Compilation Time 2023-11-16 02:13:53
Checksum 0x0025b012 (Actual: 0x0025b012)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
Digital Signature OK
Imports 20 libraries
Exports 0 functions
Resources 15 Resources
Sections 3 Sections

Version Information

CompanyName Tenorshare Co., Ltd.
FileDescription Tenorshare 4DDiG
FileVersion 2.7.17.0
LegalCopyright Copyright © 2007-2023 Tenorshare Co.,Ltd.
ProductName 20231116101323
ProductVersion 2.7.17.0
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
UPX0 0x00001000 2,580,480 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
UPX1 0x00277000 1,794,048 bytes 1,794,048 bytes 7.91 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C9563C6A786432A50D5D335289E4AA7C
.rsrc 0x0042d000 630,784 bytes 630,272 bytes 7.36 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 95DB69841A6D3E18317ABC14155A081B
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 15 (1,237,695 bytes)
Resource Type Count Total Size Percentage
ZIPRES 1 609,854 bytes
49.3%
RT_ICON 11 626,366 bytes
50.6%
RT_GROUP_ICON 1 160 bytes
0%
RT_VERSION 1 664 bytes
0.1%
RT_MANIFEST 1 651 bytes
0.1%

Certificate Chain Analysis

Certificate Information
Product 20231116101323
Description Tenorshare 4DDiG
File Version 2.7.17.0
Signing Date 02:13 AM 11/16/2023 (593 days ago)
Verification Status Signed
Signers Tenorshare Co., Ltd.; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2023; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Copyright Copyright © 2007-2023 Tenorshare Co.,Ltd.
Certificate Chain Summary
DigiCert Trusted Root G4 #1 Primary
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #2 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #3 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
DigiCert Timestamp 2023 #4 Chain
Validity Period: 2023-07-14 00:00:00 → 2034-10-13 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 05 44 AF F3 94 9D 08 39 A6 BF DB 3F 5F E5 61 16
Tenorshare Co., Ltd. #5 Chain
Validity Period: 2021-07-07 00:00:00 → 2024-07-11 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 01 70 C5 D8 E6 2A BA C7 DB 20 91 8F 8C 95 B7 E8

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
6 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware