Gridinsoft Logo
File Icon

The jdownloader-0-9-581-es-win.exe (JDownloader Setup for Windows) File Analysis

Technical Analysis

File Name jdownloader-0-9-581-es-win.exe
File Type
Win32 EXE
Magic Bytes PE32 executable for MS Windows (GUI) Intel 80386 32-bit
SSDEEP Hash
1536:mwDJZGrZopISbAoR8BXJXc9R9lFBtRThFTb0B9htz1Y:3DJ0rZo6StCBXJU7BtNA+
Scanner Version 1.0.143.174
Database Version 2023-10-18 21:04:36 UTC

Suspicious File Detected

Detected by 8 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.

InstallCore is a software distribution framework used by developers. It is often associated with potentially unwanted programs and adware through software bundling without clear user consent.
12%
Detection Rate
76,456
File Size (bytes)
8/67
Engines Detected
2023-10-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6a72c470371b4ca7777161f8f015beeb
SHA1
81edc1a47e42fed4ee063c8947d6f70cef95ba9f
SHA256
830150b51a97d073d19b5e399bc132c3e96483dd95649a848401a78aaf4d1fcf
SHA512
4ad527bf2a402d484d0646576db9faebb28b8bf0da90fc82a3b62e337a290418318793766d9f836b39076a8ff9cd54e5e1f80d6f4d0142ebcb35641fdfa66d6a
ImpHash
59a4a44a250c4cf4f2d9de2b3fe5d95f

Security Engines with Detections (8 of 67)

Elastic
malicious (moderate confidence) Malicious
CrowdStrike
win/grayware_confidence_60% (D) Malicious
VirIT
Adware.Win32.InstallCore.OI Malicious
APEX
Malicious Malicious
DrWeb
Adware.InstallCore.372 Malicious
Zillya
Trojan.InstallCoreCRTD.Win32.4133 Malicious
Microsoft
PUADlManager:Win32/InstallCore Malicious
VBA32
suspected of Trojan.Downloader.gen Malicious
59 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: e705bda601593e5e2eaa1fd4a76936e7
Fuzzy: ef7aa00dda7d54f4d6718ce73adf7596
dHash: a7cdcedecca490b8
Image Base 0x00400000
Entry Point 0x00403219
Compilation Time 2013-12-25 05:01:35
Checksum 0x000227df (Actual: 0x000227df)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Digital Signature SignerInfo.version must be 1, not 0
Imports 8 libraries
KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION
Exports 0 functions
Resources 13 Resources
Sections 5 Sections

Digital Signatures

GlobalSign Root CA GlobalSign nv-sa (BE)
UTN-USERFirst-Object COMODO CA Limited (GB)
GlobalSign CodeSigning CA - G2 AppWork GmbH (DE)

Version Information

CompanyName AppWork GmbH
CompanyWebsite http://www.jdownloader.org
FileDescription JDownloader Setup for Windows
FileVersion 2.0.0.2
LegalCopyright AppWork GmbH
ProductName JDownloader
ProductVersion 2.0.0.2
Translation 0x0409 0x0000

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 23,524 bytes 23,552 bytes 6.48 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ A9339C1BDB66ABF46DDE2CD3394FF34A
.rdata 0x00007000 4,558 bytes 4,608 bytes 5.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5801D712ECBA58AA87D1E7D1AA24F3AA
.data 0x00009000 108,504 bytes 1,024 bytes 4.94 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FB9D2533BE3EF4D00846E8AF39BD7737
.ndata 0x00024000 57,344 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x00032000 22,776 bytes 23,040 bytes 5.03 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 37CF7A8FBDDC9C53CDFC7017B207703F

Resource Analysis

Total Resources: 13 (21,998 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 19,672 bytes
89.4%
RT_DIALOG 3 1,000 bytes
4.5%
RT_GROUP_ICON 1 104 bytes
0.5%
RT_VERSION 1 692 bytes
3.1%
RT_MANIFEST 1 530 bytes
2.4%

Certificate Chain Analysis

Certificate #1
Subject GlobalSign CodeSigning CA - G2
GlobalSign nv-sa
BE
Issuer GlobalSign Root CA
Serial Number 4835703278459819397297500
Certificate #2
Subject COMODO Time Stamping Signer
COMODO CA Limited
GB
Issuer UTN-USERFirst-Object
Serial Number 95094624683456538184202721901085657022
Certificate #3
Subject AppWork GmbH
AppWork GmbH
DE
Issuer GlobalSign CodeSigning CA - G2
Serial Number 1492324647912429797733351674142397412787610
Certificate Verification Status

SignerInfo.version must be 1, not 0

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
8 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware