737MAX Plugin exe Stealer Keylogger File Malware Analysis: a0dbbc40d47b70c220d2d22877b1420d
Gridinsoft Logo
File Icon

737MAX_Plugin.exe Stealer Keylogger Analysis

Technical Analysis

File Name 737MAX_Plugin.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.227.174
Database Version 2025-10-13 00:00:17 UTC

Spy.Win64.Keylogger.ca

Malware family: Keylogger

Keylogger malware records user keystrokes including sensitive information such as passwords and financial data. It operates covertly to steal personal and confidential information.
N/A
Detection Rate
1,835,520
File Size (bytes)
2025-10-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a0dbbc40d47b70c220d2d22877b1420d
SHA1
384e2f505dcac8d61ce053ed985138bdb349fbca
SHA256
98e529b4586f4b95db9dabb544519a6faac51748610c3b24069367400bf77e50
SHA512
d9e263fc909459590c18f74d2f985c39918bc96f883bdc18b529934fc5c39c25dc981debc88297e72992a81581239efc2e1737edb947c94c3bdcd3dc1bf8d18e
ImpHash
08939e1fc623ab864e0b870dcc0b799d

PE Analysis

Basic Information

Icon
Hash: cfc7269fb7e7cd5c79218852f5c5679b
Fuzzy: 54cd975825ee66d316fc8970e119ce0d
dHash: 9ccce1f9d9d8d2f6
Image Base 0x140000000
Entry Point 0x1405f9cb0
Compilation Time 2024-12-20 15:55:41
Checksum 0x00000000 (Actual: 0x001c3b04)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 20 libraries
Exports 0 functions
Resources 752 Resources
Sections 3 Sections

Version Information

CompanyName TODO: <Company name>
FileDescription 737MAX_Plugin
FileVersion 1.0.0.1
InternalName 737MAX_Plugin.exe
LegalCopyright TODO: (c) <Company name>. All rights reserved.
OriginalFilename 737MAX_Plugin.exe
ProductName TODO: <Product name>
ProductVersion 1.0.0.1
Translation 0x0804 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
UPX0 0x00001000 4,550,656 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
UPX1 0x00458000 1,716,224 bytes 1,712,640 bytes 7.92 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE AD7855483B36FA82B2F791C99A0B138C
.rsrc 0x005fb000 122,880 bytes 121,856 bytes 4.54 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A00DF9344E00146B3D1006142168F37D
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 752 (1,331,674 bytes)
Resource Type Count Total Size Percentage
AFX_DIALOG_LAYOUT 4 8 bytes
0%
PNG 553 1,012,317 bytes
76%
STYLE_XML 5 83,741 bytes
6.3%
RT_CURSOR 28 8,496 bytes
0.6%
RT_BITMAP 46 158,460 bytes
11.9%
RT_ICON 22 47,194 bytes
3.5%
RT_MENU 1 216 bytes
0%
RT_DIALOG 27 13,160 bytes
1%
RT_STRING 30 5,528 bytes
0.4%
RT_GROUP_CURSOR 27 554 bytes
0%
RT_GROUP_ICON 5 338 bytes
0%
RT_VERSION 1 816 bytes
0.1%
RT_MANIFEST 1 794 bytes
0.1%
None 2 52 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Spy.Win64.Keylogger.ca Removal

Gridinsoft has the capability to identify and eliminate Spy.Win64.Keylogger.ca without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware