Gridinsoft Logo
File Icon

The DropCheats.exe File Analysis

Technical Analysis

File Name DropCheats.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
SSDEEP Hash
24576:N0aH9KAVOLwIXrVdJxC2gLfyam1oyFuKKBlgR+Rf6okY4QkvbCDawnVpnUY:NN9VmwI/JxC2gL7m1oyLOlgRWf60VbUY
Scanner Version 1.0.218.174
Database Version 2025-06-21 01:00:24 UTC

Suspicious File Detected

Detected by 29 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
40%
Detection Rate
15,747,921
File Size (bytes)
29/72
Engines Detected
2025-06-21
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6ddeeaa1e804463a7cdef7ff791493ca
SHA1
00c9f51bc636df50670df2566ee8c677bc6444e9
SHA256
88454d9b05cc4adf03d4499af5e5ada6043e355d95f3e17be010a8c2291a69cc
SHA512
eeed177e314df9ef201a3ef4d79eecfb4d962a8f908a26ac33e8ec26bb11faea10b823c11defb5653d22298101b332ded3d835740a14a24e8274cce131cdcfca
ImpHash
bf95d1fc1d10de18b32654b123ad5e1f

Security Engines with Detections (29 of 72)

Bkav
W32.AIDetectMalware Malicious
Lionic
Trojan.Win32.Runner.m!c Malicious
AVG
Win32:Malware-gen Malicious
Elastic
malicious (high confidence) Malicious
CTX
exe.trojan.runner Malicious
Skyhigh
Artemis!Trojan Malicious
Cylance
Unsafe Malicious
Sangfor
Trojan.Win32.Runner.V1bx Malicious
CrowdStrike
win/malicious_confidence_60% (W) Malicious
huorong
Trojan/Runner.dj Malicious
Symantec
Scr.NSISPacker!g2 Malicious
Cynet
Malicious (score: 99) Malicious
Paloalto
generic.ml Malicious
Kaspersky
HEUR:Backdoor.Win32.Agent.gen Malicious
Avast
Win32:Malware-gen Malicious
Rising
Trojan.Runner/NSIS!1.12DC1 (CLASSIC) Malicious
F-Secure
Dropper.DR/AVI.Agent.jnxzk Malicious
McAfeeD
ti!88454D9B05CC Malicious
Sophos
Mal/Generic-S Malicious
Ikarus
Trojan.NSIS.Runner Malicious
GData
Win32.Trojan.Agent.G7KIRC Malicious
Avira
DR/AVI.Agent.jnxzk Malicious
Microsoft
Trojan:Win64/LummaStealer!rfn Malicious
AhnLab-V3
Infostealer/Win.Rhadamanthys.R708982 Malicious
Malwarebytes
Spyware.Lumma Malicious
TrellixENS
Artemis!6DDEEAA1E804 Malicious
Fortinet
NSIS/Runner.DMC!tr Malicious
DeepInstinct
MALICIOUS Malicious
alibabacloud
Backdoor:Win/LummaStealer.Gen Malicious
43 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 1c1a76948c2cd9261b98ba3e48f68bd4
Fuzzy: 66ee467d1dc574286af8f5f2478ee4c3
dHash: 4000e8d4d4680040
Image Base 0x00400000
Entry Point 0x004033e9
Compilation Time 2010-04-10 12:19:23
Checksum 0x00000000 (Actual: 0x00f0d0e8)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 8 libraries
KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION
Exports 0 functions
Resources 8 Resources
Sections 5 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 25,152 bytes 25,600 bytes 6.42 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 1A752074FCD11165F6F148EA63EBE068
.rdata 0x00008000 6,346 bytes 6,656 bytes 4.88 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7EB0899A4B6211F8BC545228417D92AD
.data 0x0000a000 419,452 bytes 512 bytes 1.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B0B1D7C362F8CC76541B7FCE5014E602
.ndata 0x00071000 675,840 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x00116000 43,936 bytes 44,032 bytes 6.57 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 00791F5451EBDA4F176046C09F6640A4
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 8 (43,430 bytes)
Resource Type Count Total Size Percentage
RT_ICON 3 42,022 bytes
96.8%
RT_DIALOG 3 636 bytes
1.5%
RT_GROUP_ICON 1 48 bytes
0.1%
RT_MANIFEST 1 724 bytes
1.7%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
29 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware