| File Name | rc7.exe |
| File Type |
PE32+ executable (console) x86-64, for MS Windows
|
| Scanner Version | 1.0.228.174 |
| Database Version | 2025-11-08 19:00:25 UTC |
No threats detected by our scanner
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
0c6415d57085f0555eff51689fdf2115
|
|
| SHA1 |
c1738127a71ed309109e2bc2cbe60eb10abb7b03
|
|
| SHA256 |
818161d324eec9a7ac9beea6b2d87a991dc9686232c139809d74777e65654528
|
|
| SHA512 |
f7f79d01f0357e7c5a93654c37e757de46b1fd1ef12312fd9bcf92a8f6a1012cfb37ee6488eb23a56119e061909c79134db6309a035257f5e93fa490cc8a9e73
|
|
| ImpHash |
1d4d5476549eae86042d765defb55180
|
| Image Base | 0x140000000 |
| Entry Point | 0x1400013f0 |
| Compilation Time | 2025-11-08 17:51:19 |
| Checksum | 0x00012d40 (Actual: 0x00012d40) |
| OS Version | 4.0 |
| PEiD Signatures |
PE32+ executable (console) x86-64, for MS Windows
|
| Digital Signature | No valid SignedData structure was found. |
| Imports |
10 libraries
KERNEL32, api-ms-win-crt-environment-l1-1-0, api-ms-win-crt-filesystem-l1-1-0, api-ms-win-crt-heap-l1-1-0, api-ms-win-crt-locale-l1-1-0, api-ms-win-crt-math-l1-1-0, api-ms-win-crt-private-l1-1-0, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-stdio-l1-1-0, api-ms-win-crt-string-l1-1-0 |
| Exports | 0 functions |
| Resources | 0 Resources |
| Sections | 16 Sections |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
6,368 bytes | 6,656 bytes | 5.83 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B4D4BC369F02CE21BA53E55A4C141F3E |
.data |
0x00003000 |
160 bytes | 512 bytes | 0.58 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1E7D8BE824433CD6D8423A27CA5CC0C5 |
.rdata |
0x00004000 |
1,624 bytes | 2,048 bytes | 3.65 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
DD94E19EDED0D63C10E7EBD3EDAF1F15 |
.pdata |
0x00005000 |
564 bytes | 1,024 bytes | 2.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
5B37863017EFC047D051B7DB17EBA697 |
.xdata |
0x00006000 |
452 bytes | 512 bytes | 3.61 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0400F0F3475A2BD27E545A4295D1FD55 |
.bss |
0x00007000 |
384 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x00008000 |
2,216 bytes | 2,560 bytes | 3.58 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8D201FA499A0EB1A297B32F542A7EF91 |
.tls |
0x00009000 |
16 bytes | 512 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BF619EAC0CDF3F68D496EA9344137E8B |
.reloc |
0x0000a000 |
100 bytes | 512 bytes | 1.29 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
7221FC6AD7FBDBF63C45ED7B1FF26CB8 |
/4 |
0x0000b000 |
80 bytes | 512 bytes | 0.24 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
E68B4191D4EC798C15F3073CC2944DEB |
/19 |
0x0000c000 |
4,518 bytes | 4,608 bytes | 5.20 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
3825F610FE42F007FD5639491C159653 |
/31 |
0x0000e000 |
181 bytes | 512 bytes | 2.21 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
16B80C9B89F230DEA98DFD24D54FF448 |
/45 |
0x0000f000 |
164 bytes | 512 bytes | 1.49 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
C2CA53F05C89A3287CA044B8FF66D1EF |
/57 |
0x00010000 |
72 bytes | 512 bytes | 0.70 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
7256CEA0EFAE0E2EC864FF1A081DD520 |
/70 |
0x00011000 |
163 bytes | 512 bytes | 2.47 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
A1D1944493FA54D5183E0C93DF1C3A0D |
/81 |
0x00012000 |
504 bytes | 512 bytes | 4.88 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
6295444EF22C68D37B3DC06D6B2CF533 |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!