The CMH1 4 93fa5 exe File Malware Analysis
Gridinsoft Logo

The CMH1.4.93fa5.exe File Analysis

Technical Analysis

File Name CMH1.4.93fa5.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
98304:PtdaWKI2m0VV1ZPwX7lfYqHcbFodyC2z52gxxyeZI:P2WarVV1ZYXZneFUyC2l2rs
Scanner Version 1.0.231.174
Database Version 2026-01-05 02:00:47 UTC

Suspicious File Detected

Detected by 22 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
31%
Detection Rate
4,787,200
File Size (bytes)
22/72
Engines Detected
2026-01-05
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
8cca49c5bb4c69ac3e9cc13f66b981fb
SHA1
8597dab7df56564ecc27791b2b12d7d5e4d95891
SHA256
94f2a435eca2cb6d79f3c0ea70e5f5251e0df8c39f63118ec7b3947f760b539d
SHA512
8ab2285738add461ec1454f542980f394849a9448298733bb22b22f48b9e7b524a8f3072298743ee77b75ffc0d525af8879749e79fafb4f64ee2ab6ed7d18576
ImpHash
6c98d37a5bd4b681f9cdcb2c8b1fa5dc

Security Engines with Detections (22 of 72)

Bkav
W64.AIDetectMalware Malicious
Skyhigh
BehavesLike.Win64.Generic.rc Malicious
Cylance
Unsafe Malicious
Sangfor
Suspicious.Win32.Save.a Malicious
CrowdStrike
win/malicious_confidence_100% (D) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Elastic
malicious (high confidence) Malicious
ESET-NOD32
Win64/Packed.VMProtect.L suspicious application Malicious
Cynet
Malicious (score: 100) Malicious
Sophos
Mal/VMProtBad-A Malicious
McAfeeD
Real Protect-LS!8CCA49C5BB4C Malicious
SentinelOne
Static AI - Malicious PE Malicious
Trapmine
malicious.moderate.ml.score Malicious
Ikarus
Trojan.Win64.Vmprotect Malicious
Google
Detected Malicious
Microsoft
PUA:Win32/Puwaders.C!ml Malicious
ZoneAlarm
Mal/VMProtBad-A Malicious
AhnLab-V3
Malware/Win.VMProtect.R704662 Malicious
DeepInstinct
MALICIOUS Malicious
Malwarebytes
Malware.AI.933095926 Malicious
APEX
Malicious Malicious
MaxSecure
Trojan.Malware.300983.susgen Malicious
50 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1407a76b4
Compilation Time 2025-09-19 07:20:38
Checksum 0x00000000 (Actual: 0x0049518a)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 20 libraries
Exports 0 functions
Resources 1 Resources
Sections 8 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,580,174 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00183000 421,010 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x001ea000 946,520 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.pdata 0x002d2000 68,208 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
_RDATA 0x002e3000 244 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.vmp0 0x002e4000 1,711,488 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.vmp1 0x00486000 4,785,540 bytes 4,785,664 bytes 7.86 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BA9418F9D421688CE6F828A86FD88218
.rsrc 0x00917000 480 bytes 512 bytes 4.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5A8953F1CD6E826DE3C2CD8595EFC21C
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 1 (392 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 392 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
22 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware