Gridinsoft Logo
File Icon

The NoBot.exe (NoBot) File Analysis

Technical Analysis

File Name NoBot.exe
File Type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Scanner Version 1.0.223.174
Database Version 2025-08-31 09:00:47 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,729,016
File Size (bytes)
2025-08-31
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
7136d2f78f8be00d92ce7bd047c59462
SHA1
3f42c3e5d56300659e2881c0699f6b74bb5cf904
SHA256
959aceedf36620acf64c179f7587b6cc48defbf4a3148ad739fbb001a61735f6
SHA512
b9fc4381281714ce8a650ea9924d59fd1ab779807b12cb106121a316cc816cede2f40b846cbfa3e040248617aa2837497fc7916c8a4fb4b821a52477cb7bbc17
ImpHash
f34d5f2d4577ed6d9ceec516c1f5a744

PE Analysis

Basic Information

Icon
Hash: 527746d83112858906d8bc98b3cbc6ff
Fuzzy: eb413af856f2dc7789220d69b3cca06b
dHash: 0f332b4d29338e48
Image Base 0x00400000
Entry Point 0x0054a486
Compilation Time 2018-12-03 11:46:46
Checksum 0x001ad85d (Actual: 0x001ad85d)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Digital Signature OK
Imports 1 libraries
mscoree
Exports 0 functions
Resources 9 Resources
Sections 3 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00002000 1,344,652 bytes 1,345,024 bytes 7.76 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ EB288B3D02FEEFB5069360AC0AC46328
.rsrc 0x0014c000 374,544 bytes 374,784 bytes 3.09 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ F8D228957A4E561B929559F7991286EA
.reloc 0x001a8000 12 bytes 512 bytes 0.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 1E6079EF83BA618ACC64195031728800
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 9 (374,036 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 369,968 bytes
98.9%
RT_GROUP_ICON 1 90 bytes
0%
RT_VERSION 1 920 bytes
0.2%
RT_MANIFEST 1 3,058 bytes
0.8%

Certificate Chain Analysis

Certificate Information
Product NoBot
Description NoBot
File Version 1.0.5.3
Original Name NoBot.exe
Signing Date 04:41 PM 12/03/2018 (2759 days ago)
Verification Status Signed
Signers Simple IT Solutions, LLC; DigiCert SHA2 Assured ID Code Signing CA; DigiCert
Counter Signers DigiCert Timestamp Responder; DigiCert Assured ID CA-1; DigiCert
Internal Name NoBot.exe
Copyright Simple IT Solutions, LLC
Certificate Chain Summary
DigiCert Assured ID Root CA #1 Primary
Validity Period: 2006-11-10 00:00:00 → 2031-11-10 00:00:00
Signature Algorithm: sha1RSA
Serial Number: 0C E7 E0 E5 17 D8 46 FE 8F E5 60 FC 1B F0 30 39
DigiCert SHA2 Assured ID Code Signing CA #2 Chain
Validity Period: 2013-10-22 12:00:00 → 2028-10-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08
Simple IT Solutions, LLC #3 Chain
Validity Period: 2018-01-23 00:00:00 → 2019-03-20 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 0B 66 B8 C3 3A 9E 25 0E 7D BD D2 D5 CB 3F 17 0D
DigiCert Timestamp Responder #4 Chain
Validity Period: 2014-10-22 00:00:00 → 2024-10-22 00:00:00
Signature Algorithm: sha1RSA
Serial Number: 03 01 9A 02 3A FF 58 B1 6B D6 D5 EA E6 17 F0 66
DigiCert Assured ID CA-1 #5 Chain
Validity Period: 2006-11-10 00:00:00 → 2021-11-10 00:00:00
Signature Algorithm: sha1RSA
Serial Number: 06 FD F9 03 96 03 AD EA 00 0A EB 3F 27 BB BA 1B

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
This file looks clean right now, but that doesn't mean you should let your guard down. New malware appears daily, and even legit files can be compromised after download. When in doubt, verify the source and check for a digital signature.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware