Gridinsoft Logo
File Icon

The WinRAR.exe (WinRAR) File Analysis

Technical Analysis

File Name WinRAR.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.220.174
Database Version 2025-07-16 14:00:25 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,316,880
File Size (bytes)
2025-07-16
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
1d4308fde56b11100b0e8a25c6262ddd
SHA1
e8d970db0a98de10ab975e1ca8c7a24bf7ccef31
SHA256
7415b18099d47a37d187e6c94371ae81b2e600c412b215704d709348d331a3a4
SHA512
0717271146c87ede4edb0fec2d7cec1c11a04e8109339a08d80157645de7cdce907741e881af8f23ff6ff65760402cbc2e49ddef7a0a3434d23e19d67ceb0e14
ImpHash
5d51836cf354971ddc9f92fcb8789969

PE Analysis

Basic Information

Icon
Hash: b3f0266a9874e070b3ec855645687948
Fuzzy: 33d9200afee9550e4e551841fda604a1
dHash: b233333a6b3a3230
Image Base 0x140000000
Entry Point 0x1401c6ba0
Compilation Time 2025-06-23 07:50:25
Checksum 0x0032a1c5 (Actual: 0x0032a1c5)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path d:\Projects\WinRAR\build\winrar64\Release\WinRAR.pdb
Digital Signature OK
Imports 14 libraries
Exports 0 functions
Resources 359 Resources
Sections 7 Sections

Version Information

ProductName WinRAR
CompanyName Alexander Roshal
FileDescription WinRAR
FileVersion 7.12.0
ProductVersion 7.12.0
InternalName WinRAR
LegalCopyright Copyright © Alexander Roshal 1993-2025
OriginalFilename WinRAR.exe
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,028,590 bytes 2,029,056 bytes 6.54 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BDB7526C405107FDB1FCE4B06BE7E79D
.rdata 0x001f1000 328,674 bytes 328,704 bytes 5.76 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 28CB1791BDB26AC0E35C47CCB0FC6A32
.data 0x00242000 358,620 bytes 45,056 bytes 4.55 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 98CB595020A93034E10416F8B23E2CE6
.pdata 0x0029a000 52,968 bytes 53,248 bytes 6.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 657F23CB0F48CABD87C98B57B80FCDBF
.didat 0x002a7000 304 bytes 512 bytes 2.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5B6EBC2310AADD9361C138A66F04D24E
.rsrc 0x002a8000 841,136 bytes 841,216 bytes 7.15 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E7FC3192300818887EB06DE7779B5D3F
.reloc 0x00376000 7,652 bytes 7,680 bytes 5.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 31CDEC5C29EFDC0CD3440FF7B575A9B7
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 359 (820,513 bytes)
Resource Type Count Total Size Percentage
PNG 111 432,314 bytes
52.7%
RT_CURSOR 2 1,128 bytes
0.1%
RT_ICON 46 273,645 bytes
33.4%
RT_MENU 2 3,478 bytes
0.4%
RT_DIALOG 83 70,616 bytes
8.6%
RT_STRING 100 35,506 bytes
4.3%
RT_ACCELERATOR 6 544 bytes
0.1%
RT_GROUP_CURSOR 1 34 bytes
0%
RT_GROUP_ICON 6 680 bytes
0.1%
RT_VERSION 1 720 bytes
0.1%
RT_MANIFEST 1 1,848 bytes
0.2%

Certificate Chain Analysis

Certificate Information
Product WinRAR
Description WinRAR
File Version 7.12.0
Original Name WinRAR.exe
Signing Date 07:52 AM 06/23/2025 (23 days ago)
Verification Status Signed
Signers win.rar GmbH; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Internal Name WinRAR
Copyright Copyright © Alexander Roshal 1993-2025
Certificate Chain Summary
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #1 Primary
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
win.rar GmbH #2 Chain
Validity Period: 2023-08-08 00:00:00 → 2026-08-07 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 04 8B 08 39 9E C7 03 62 3C 72 CD 20 77 AD 65 D9
DigiCert Timestamp 2024 #3 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #4 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware