Gridinsoft Logo
File Icon

The Element.exe (Element) File Analysis

Technical Analysis

File Name Element.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
24576:KuJoXji9hGAQvL0bqAw280xWMkCLeWUqxqKWy/nqxTG1Q4eNu/p+ofQEFwwzvHyk:KJfiXQRKxBf3zzKkV
Scanner Version 1.0.211.174
Database Version 2025-03-28 10:01:28 UTC

Suspicious File Detected

Detected by 46 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
66%
Detection Rate
1,823,816
File Size (bytes)
46/70
Engines Detected
2025-03-28
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
53249960e9e4a37b664ceb6ae59226a6
SHA1
49081cc6f79378ce59448a80cbdf2d56898f8a5f
SHA256
9d2d1e1ac581272926c14faa37c95c337220321d2a3fb0a19d9eaf54ff57b692
SHA512
6908be2f6621078a21e697d7f6ae08763209cf4e20a39bc89f5cdf5b71b3c8ad624bdf7cbb80ac7951225bd6ebba6585068279b46db4fc6334a3e862c3ddff09
ImpHash
1aae8bf580c846f39c71c05898e57e88

Security Engines with Detections (46 of 70)

Bkav
W32.AIDetectMalware Malicious
Lionic
Trojan.Win32.Lumma.1u!c Malicious
Elastic
malicious (high confidence) Malicious
MicroWorld-eScan
Trojan.GenericKD.75933364 Malicious
CAT-QuickHeal
Trojan.Ghanarava.17424217389226a6 Malicious
ALYac
Trojan.GenericKD.75933364 Malicious
Malwarebytes
Malware.AI.209049895 Malicious
Sangfor
Trojan.Win32.Agent.Vwp4 Malicious
K7AntiVirus
Trojan ( 005c27f41 ) Malicious
K7GW
Trojan ( 005c27f41 ) Malicious
CrowdStrike
win/malicious_confidence_70% (W) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of WinGo/TrojanDropper.Agent.FW Malicious
Paloalto
generic.ml Malicious
Cynet
Malicious (score: 99) Malicious
Kaspersky
Trojan-PSW.Win32.Vidar.dfp Malicious
BitDefender
Trojan.GenericKD.75933364 Malicious
Avast
Win32:Evo-gen [Trj] Malicious
Tencent
Win32.Trojan.FalseSign.Snkl Malicious
Sophos
Troj/GoInject-B Malicious
F-Secure
Trojan.TR/Redcap.hrwwr Malicious
VIPRE
Trojan.GenericKD.75933364 Malicious
McAfeeD
ti!9D2D1E1AC581 Malicious
Trapmine
malicious.moderate.ml.score Malicious
FireEye
Trojan.GenericKD.75933364 Malicious
Emsisoft
Trojan.GenericKD.75933364 (B) Malicious
Ikarus
Trojan.WinGo.Agent Malicious
Varist
W32/ABTrojan.QSOI-3566 Malicious
Avira
TR/Redcap.hrwwr Malicious
Antiy-AVL
Trojan[PSW]/Win32.Lumma Malicious
Kingsoft
Win32.Trojan-PSW.Lumma.gen Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
Arcabit
Trojan.Generic.D486A6B4 Malicious
ZoneAlarm
Troj/GoInject-B Malicious
GData
Trojan.GenericKD.75933364 Malicious
Google
Detected Malicious
AhnLab-V3
Infostealer/Win.Generic.R694073 Malicious
McAfee
Artemis!53249960E9E4 Malicious
Cylance
Unsafe Malicious
Panda
Trj/Chgt.AD Malicious
TrendMicro-HouseCall
TROJ_GEN.R06CH09C925 Malicious
CTX
exe.trojan.lumma Malicious
Fortinet
PossibleThreat.PALLAS.M Malicious
AVG
Win32:Evo-gen [Trj] Malicious
DeepInstinct
MALICIOUS Malicious
alibabacloud
Trojan[dropper]:Multi/Wacatac.B9nj Malicious
24 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: a70aee6b293641562d87db8fa815469a
Fuzzy: 20f8ad22c2b7f29821555a0af69ceaa0
dHash: 2b33333333392b0b
Image Base 0x00400000
Entry Point 0x00470cc0
Compilation Time 1970-01-01 00:00:00
Checksum 0x001cbb9a (Actual: 0x001cbb9a)
OS Version 6.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 1 libraries
kernel32
Exports 0 functions
Resources 18 Resources
Sections 7 Sections

Version Information

FileDescription Element
FileVersion 1.11.92
InternalName Setup.exe
LegalCopyright Copyright © 2025 Element
OriginalFilename Setup.exe
ProductName Element
ProductVersion 1.11.92.0
SquirrelAwareVersion 1
CompanyName Element
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 730,455 bytes 730,624 bytes 6.16 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BA30B02447CF966CAD164632BFD5DA8F
.rdata 0x000b4000 943,724 bytes 944,128 bytes 5.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E5E9B10D5655D953452D4C4145CB8574
.data 0x0019b000 186,688 bytes 37,888 bytes 5.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B139F4F8FD138C3B641A2DDFF630B29C
.idata 0x001c9000 1,100 bytes 1,536 bytes 3.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1745C5B091E7C64AA275B4438A9AF052
.reloc 0x001ca000 40,836 bytes 40,960 bytes 6.65 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ C940DE6BEE18BC02E464BE713EB233CF
.symtab 0x001d4000 4 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 07B5472D347D42780469FB2654B7FC54
.rsrc 0x001d5000 56,431 bytes 56,832 bytes 5.82 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 90F348575CE7E59B26E66EC530900686
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 18 (55,391 bytes)
Resource Type Count Total Size Percentage
FLAGS 1 12 bytes
0%
RT_ICON 12 51,280 bytes
92.6%
RT_STRING 2 2,186 bytes
3.9%
RT_GROUP_ICON 1 174 bytes
0.3%
RT_VERSION 1 740 bytes
1.3%
RT_MANIFEST 1 999 bytes
1.8%

Certificate Chain Analysis

Certificate Information
Product Element
Description Element
File Version 1.11.92
Original Name Setup.exe
Signing Date 02:59 PM 02/11/2025 (114 days ago)
Verification Status The digital signature of the object did not verify.
Signers NEW VECTOR LTD; SSL.com EV Code Signing Intermediate CA RSA R3; SSL.com EV Root Certification Authority RSA R2
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Internal Name Setup.exe
Copyright Copyright © 2025 Element
Certificate Chain Summary
NEW VECTOR LTD #1 Primary
Validity Period: 2023-03-17 15:47:01 → 2026-03-16 15:47:01
Signature Algorithm: sha256RSA
Serial Number: 46 16 64 C4 1A DD F5 ED 7F 52 8D 55 05 8D 25 0E
SSL.com EV Code Signing Intermediate CA RSA R3 #2 Chain
Validity Period: 2019-03-26 17:44:23 → 2034-03-22 17:44:23
Signature Algorithm: sha256RSA
Serial Number: 42 4B 6A 53 CE C7 66 14 1C 2A 63 B1 A5 1C 41 04
DigiCert Timestamp 2024 #3 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #4 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
46 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware