Gridinsoft Logo
File Icon

The winrar-x64-621ru.exe (WinRAR archiver) File Analysis

Technical Analysis

File Name winrar-x64-621ru.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.144.174
Database Version 2023-10-31 11:02:56 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,742,960
File Size (bytes)
2023-10-31
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
5f966b8d0f33e65b1b07fa304ba592e5
SHA1
c5a3c348ab9b8c98046727aebba4ce2f746e6057
SHA256
74646a5d9f746c4036631bbbb373a9ecfa3cc3a4b911deb71d0e3f1473cb88d6
SHA512
3dc3d00bf29c2c2e3675fc6d2e5887a1dc5aa883bba03b493d5a6b84a1975016588351409945a59f12aec8c434eb09116f5885ba06cd50f62e8625ee48478a9b
ImpHash
93b9d508050f74b56e67b9b55c5a60f4

PE Analysis

Basic Information

Icon
Hash: d4a9c34f7171828c8adc9c3a0307afb8
Fuzzy: 2ea515c30e1a6ee8ad367944867f72e8
dHash: b233332a6b2ab232
Image Base 0x140000000
Entry Point 0x140025320
Compilation Time 2023-02-16 12:31:41
Checksum 0x0039faee (Actual: 0x0039faee)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path D:\Projects\WinRAR\sfx\setup\build\sfxrar64\Release\sfxrar.pdb
Digital Signature OK
Imports 3 libraries
KERNEL32, OLEAUT32, gdiplus
Exports 0 functions
Resources 25 Resources
Sections 8 Sections

Digital Signatures

GlobalSign GlobalSign nv-sa (BE)
GlobalSign CodeSigning CA - SHA256 - G3 win.rar GmbH (DE)
DigiCert Assured ID Root CA DigiCert Inc (US)
DigiCert Trusted Root G4 DigiCert, Inc. (US)
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA DigiCert (US)

Version Information

ProductName WinRAR
CompanyName Alexander Roshal
FileDescription WinRAR archiver
FileVersion 6.21.0
ProductVersion 6.21.0
InternalName WinRAR
LegalCopyright Copyright © Alexander Roshal 1993-2023
OriginalFilename WinRAR.exe
Translation 0x0419 0x04e3

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 250,014 bytes 250,368 bytes 6.51 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3B09718F91364436790CE10A71105786
.rdata 0x0003f000 66,038 bytes 66,048 bytes 5.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 36C5E5F845C255D69699275CD49F09EA
.data 0x00050000 152,948 bytes 5,120 bytes 3.70 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 816906E83F771D9A4B25E43BF8D36DAB
.pdata 0x00076000 11,580 bytes 11,776 bytes 5.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 35FE6AB302FEE25751EBCB6DE339B16A
.didat 0x00079000 776 bytes 1,024 bytes 2.72 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE EE2F46922DA19D66C4EDD9983A9A02FE
_RDATA 0x0007a000 348 bytes 512 bytes 3.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 542A6DBF24D3142530D2EC51DD992ADD
.rsrc 0x0007b000 159,744 bytes 156,160 bytes 7.79 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E74F6FD9452E5F64DE54F230CE6A53D7
.reloc 0x000a2000 2,316 bytes 2,560 bytes 5.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ CDD2F258B98EDEF9C659067796047B48
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 25 (154,258 bytes)
Resource Type Count Total Size Percentage
PNG 2 69,432 bytes
45%
RT_ICON 7 77,238 bytes
50.1%
RT_DIALOG 4 2,222 bytes
1.4%
RT_STRING 9 2,654 bytes
1.7%
RT_GROUP_ICON 1 104 bytes
0.1%
RT_VERSION 1 736 bytes
0.5%
RT_MANIFEST 1 1,872 bytes
1.2%

Certificate Chain Analysis

Certificate #1
Subject GlobalSign CodeSigning CA - SHA256 - G3
GlobalSign nv-sa
BE
Issuer GlobalSign
Serial Number 1462505465907667685259976282102477
Certificate #2
Subject win.rar GmbH
win.rar GmbH
DE
Issuer GlobalSign CodeSigning CA - SHA256 - G3
Serial Number 35626140423967868457733424021
Certificate #3
Subject DigiCert Trusted Root G4
DigiCert Inc
US
Issuer DigiCert Assured ID Root CA
Serial Number 19414496059604725969669510860671817818
Certificate #4
Subject DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
DigiCert, Inc.
US
Issuer DigiCert Trusted Root G4
Serial Number 9586110043380832440035821245782711899
Certificate #5
Subject DigiCert Timestamp 2022 - 2
DigiCert
US
Issuer DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
Serial Number 16352681515936560713148055516499426650
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware