File Name | x-vpn-anti-track-and-unblock-76-4-4386.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
Scanner Version | 1.0.192.174 |
Database Version | 2024-10-10 10:00:22 UTC |
Malware family: Downloader
Hash Type | Value | Action |
---|---|---|
MD5 |
9f57c009b64bfaa0d55445f07cd8c34a
|
|
SHA1 |
e9827cea1f6907c129a2ae31ad1153812669167e
|
|
SHA256 |
75ba740fc658a31ebf081d368e4fade4584e89b9108cbe6cdd6ea2b44ccb0d6a
|
|
SHA512 |
148ecc5e454e95da7591dc110314587dc8cb9e07ceadd1322cd3761ca1b012486ac90c54e982a387f306eadffc016a03d24a173f8bad387c8fc0f1534f389675
|
|
ImpHash |
61259b55b8912888e90f516ca08dc514
|
Icon |
Hash: f92cacc423d3f11772d25dc4b3baf75d
Fuzzy: ebaeed70225333e3765939c0603c815c dHash: d4aa92cece17aad4 |
Image Base | 0x00400000 |
Entry Point | 0x00403640 |
Compilation Time | 2021-09-25 21:56:47 |
Checksum | 0x024deb90 (Actual: 0x024deb90) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
Digital Signature | OK |
Imports |
7 libraries
ADVAPI32, SHELL32, ole32, COMCTL32, USER32, GDI32, KERNEL32 |
Exports | 0 functions |
Resources | 12 Resources |
Sections | 5 Sections |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
26,230 bytes | 26,624 bytes | 6.42 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
6F5ABE9EEDA26EE84B3C1ED1A6C82001 |
.rdata |
0x00008000 |
5,018 bytes | 5,120 bytes | 5.14 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8C5EDFD8FF9CC0135E197611BE38CA18 |
.data |
0x0000a000 |
131,960 bytes | 1,536 bytes | 4.11 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
4B2421975C21B032F7EA000F5E7F9FBF |
.ndata |
0x0002b000 |
163,840 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x00053000 |
51,760 bytes | 52,224 bytes | 7.12 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
881F0E1C5B86D3A5FC31BA568BA0CCF2 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_BITMAP | 1 | 1,638 bytes | |
RT_ICON | 4 | 46,625 bytes | |
RT_DIALOG | 5 | 1,632 bytes | |
RT_GROUP_ICON | 1 | 62 bytes | |
RT_MANIFEST | 1 | 1,070 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Adware.Win32.Downloader.dd!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system