Gridinsoft Logo
File Icon

The runsc.exe (Microsoft ® Windows Based Script Host) File Analysis

Technical Analysis

File Name runsc.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
3072:SWmu8z+jLBMjiQLzHTUYvVUvoxR7nT7unQWeUJqNg1BxknCM3FTxteTo:SWm1WLB0tnmA+QWecqNgNM1TaTo
Scanner Version 1.0.169.174
Database Version 2024-03-15 13:00:19 UTC

Suspicious File Detected

Detected by 24 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
33%
Detection Rate
141,824
File Size (bytes)
24/73
Engines Detected
2024-03-15
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c3b028442b308a50d08fd22ed5f9fca1
SHA1
91de275c83e149101a3664a0c3de69e6d6422b5e
SHA256
817110a1014d9f49063f48c85f22aaf366ad670f31956a7c62d91d7cecb8d42c
SHA512
047a9c897b3395137f5b7b11b18ab7edb51f7a61a30154c3200c296d67df26308dba395bfe264cba1075e4f75b012e457695e799a4e523d240b45290ba7316c6
ImpHash
317c8de06f7aee57a3acf4722fe00983

Security Engines with Detections (24 of 73)

Bkav
W32.AIDetectMalware Malicious
Elastic
malicious (high confidence) Malicious
Skyhigh
BehavesLike.Win32.Virut.cm Malicious
Cylance
unsafe Malicious
Symantec
ML.Attribute.HighConfidence Malicious
tehtris
Generic.Malware Malicious
Cynet
Malicious (score: 100) Malicious
APEX
Malicious Malicious
Avast
Win32:Evo-gen [Trj] Malicious
F-Secure
Trojan.TR/Patched.Ren.Gen Malicious
Trapmine
malicious.high.ml.score Malicious
FireEye
Generic.mg.c3b028442b308a50 Malicious
Sophos
Generic ML PUA (PUA) Malicious
Ikarus
Virtob.Win32 Malicious
Avira
TR/Patched.Ren.Gen Malicious
Antiy-AVL
Virus/Win32.Virut.a Malicious
Microsoft
Program:Win32/Wacapew.C!ml Malicious
Google
Detected Malicious
Rising
[email protected] (RDML:GMoHo3CiZb72eVVodtsDzQ) Malicious
SentinelOne
Static AI - Malicious PE Malicious
BitDefenderTheta
Gen:NN.ZexaCO.36802.iq0@ayPLbDhi Malicious
AVG
Win32:Evo-gen [Trj] Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/malicious_confidence_60% (D) Malicious
49 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 3e9f37650d2738f57fdc6ba2dd9ad379
Fuzzy: cbeee02d129f2ded45884f420361d51b
dHash: 2c4c1068ac2c6c10
Image Base 0x01000000
Entry Point 0x01002f3b
Compilation Time 2005-05-16 04:41:55
Checksum 0x00000000 (Actual: 0x00029700)
OS Version 6.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path wscript.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 7 libraries
ADVAPI32, KERNEL32, USER32, msvcrt, OLEAUT32, ole32, VERSION
Exports 1 functions
Resources 30 Resources
Sections 4 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft ® Windows Based Script Host
FileVersion 5.8.7601.24288
InternalName wscript.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename wscript.exe
ProductName Microsoft ® Windows Script Host
ProductVersion 5.8.7601.24288
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 95,632 bytes 95,744 bytes 6.32 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE AFE0CAE7282BFC05A2EE473A9C5F7D97
.data 0x00019000 1,244 bytes 1,536 bytes 0.76 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 69692ED6DD0FFE43A07DA98D4100D842
.rsrc 0x0001a000 38,072 bytes 38,400 bytes 4.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BED71D1971DE84FB207D556381984B07
.reloc 0x00024000 33,792 bytes 5,120 bytes 6.58 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C81EED06AE4A2E262FE3A825F03441A4
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 30 (36,378 bytes)
Resource Type Count Total Size Percentage
MUI 1 224 bytes
0.6%
TYPELIB 2 23,916 bytes
65.7%
RT_ICON 8 4,160 bytes
11.4%
RT_STRING 14 7,054 bytes
19.4%
RT_GROUP_ICON 4 136 bytes
0.4%
RT_VERSION 1 888 bytes
2.4%

Certificate Chain Analysis

Certificate Information
Product Microsoft ® Windows Script Host
Description Microsoft ® Windows Based Script Host
File Version 5.8.7601.24288
Original Name wscript.exe
Internal Name wscript.exe
Copyright © Microsoft Corporation. All rights reserved.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
24 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware