File Name | PotatoGraphics.exe |
File Type |
Win32 EXE
|
Magic Bytes | PE32 executable (GUI) Intel 80386, for MS Windows |
SSDEEP Hash |
1572864:8Wl164XEQCrwvXoTXkcpDNNEfxPJc9XIr1lAZ1POJC6X/1B+i3j:8y640cAQ656xPJc9k1lfhWiT
|
Scanner Version | 1.0.210.174 |
Database Version | 2025-03-14 13:00:54 UTC |
Detected by 5 security engines - requires caution
Hash Type | Value | Action |
---|---|---|
MD5 |
f73b7791baeb98ce6c6f6b7f82e1792d
|
|
SHA1 |
3b1620b7a105b3ffa6c248f020cbee1119211952
|
|
SHA256 |
7533c3d88c4ff72273d982f53faf9cfa04a7ca51dae4c481512663514872d21d
|
|
SHA512 |
dc4cdca7ece2beb159bb1ed316e61b4334931307351ca3799593c47dc706164454e874aa23ffcbd2c8787ab7d2456068c3bc054800d6d727bec8ad700a4d321c
|
|
ImpHash |
df453def9d4f8f1453a5fa51c6608cfc
|
Image Base | 0x00400000 |
Entry Point | 0x008fa050 |
Compilation Time | 2023-10-31 14:59:22 |
Checksum | 0x00000000 (Actual: 0x04026c3a) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | D:\a\_work\1\s\artifacts\obj\coreclr\windows.x86.Release\Corehost.Static\singlefilehost.pdb |
Digital Signature | No valid SignedData structure was found. |
Imports | 17 libraries |
Exports | 5 functions |
Resources | 5 Resources |
Sections | 8 Sections |
Translation | 0x0000 0x04b0 |
CompanyName | PotatoGraphics |
FileDescription | PotatoGraphics |
FileVersion | 1.0.0.0 |
InternalName | PotatoGraphics.dll |
LegalCopyright | |
OriginalFilename | PotatoGraphics.dll |
ProductName | PotatoGraphics |
ProductVersion | 1.0.0 |
Assembly Version | 1.0.0.0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
5,572,874 bytes | 5,573,120 bytes | 6.56 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
7AD59DCF80AFCBA46BB6779381710378 |
.CLR_UEF |
0x00552000 |
68 bytes | 512 bytes | 0.96 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
57BC74EDCAE15B11802D7FF93D25B76A |
.rdata |
0x00553000 |
1,307,630 bytes | 1,307,648 bytes | 5.13 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A81CB89E48FC1A139C5BD873361779E1 |
.data |
0x00693000 |
81,084 bytes | 29,184 bytes | 3.87 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9EBA1EFE4F91CDE198B04E2A6523BD9D |
.didat |
0x006a7000 |
28 bytes | 512 bytes | 0.25 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
F0474F498313864F0BEDB9BB443E88CF |
_RDATA |
0x006a8000 |
69,392 bytes | 69,632 bytes | 5.36 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
211089D7D672E1712B48C26D0BDC0A1B |
.rsrc |
0x006b9000 |
1,268,452 bytes | 1,268,736 bytes | 6.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6A924232B319F0A79417DB80C6464134 |
.reloc |
0x007ef000 |
268,556 bytes | 268,800 bytes | 6.67 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
0BDA70936AE3F88B8B17230BF231D2D3 |
2 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_RCDATA | 3 | 1,266,776 bytes | |
RT_VERSION | 1 | 764 bytes | |
RT_MANIFEST | 1 | 436 bytes |
Product | PotatoGraphics |
Description | PotatoGraphics |
File Version | 1.0.0.0 |
Original Name | PotatoGraphics.dll |
Internal Name | PotatoGraphics.dll |
33 00 00 05 15 B0 EF 41 0F A4 18 8F B1 00 00 00 00 05 15
61 0C 52 4C 00 00 00 00 00 03
33 00 00 01 D1 B2 5B 40 28 6C 2E D2 45 00 01 00 00 01 D1
33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
✓ This file has been digitally signed and the certificate chain has been verified
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important