Gridinsoft Logo
File Icon

The Setup.exe (Hex Editor Neo Setup Package) File Analysis

Technical Analysis

File Name Setup.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
1572864:/1cm5p65b8MMuch1cm5p65b8MMucH1cm5p65b8MMuc8:/Z5sb8MMlhZ5sb8MMlHZ5sb8MMl8
Scanner Version 1.0.215.174
Database Version 2025-04-29 01:00:23 UTC

Suspicious File Detected

Detected by 9 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
13%
Detection Rate
66,726,700
File Size (bytes)
9/71
Engines Detected
2025-04-29
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
f15af175fd7df57280ad0b850a2f4711
SHA1
7f81d29432d81c90fd50b1266cf9add1ac4b5ac3
SHA256
9e7d1a41d809d7933d7f3cec5f45e53f0bb1436a99dc76cad1ba3c8368dadc61
SHA512
dde9eb74833a8ebca390037e3f3509b6980ae9ddb977502b3ccd6eceff3721c98ff9cd9e072254944ea9769a43301ec15fa10a1bd4cb5b2b559a5082ff0f321f
ImpHash
9da7641a251ed4e6f1102b982119761f

Security Engines with Detections (9 of 71)

Bkav
W32.AIDetectMalware Malicious
Skyhigh
Artemis Malicious
VirIT
Trojan.Win32.GenHeur.B Malicious
Rising
Trojan.Injector!1.127AD (CLASSIC) Malicious
McAfeeD
ti!9E7D1A41D809 Malicious
Trapmine
suspicious.low.ml.score Malicious
Webroot
Win.Infostealer.Lumma Malicious
Cylance
Unsafe Malicious
Fortinet
W32/PossibleThreat Malicious
62 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 8092d5a734ad6345035601c9548e34a8
Fuzzy: cab4aa86fdbca58160b85aa9034587c7
dHash: fef6e6e6cace3171
Image Base 0x00400000
Entry Point 0x00407de0
Compilation Time 2023-07-03 11:36:59
Checksum 0x03fa32ca (Actual: 0x03fa5fa1)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\MyProjects\Elizabeth3\out\SfxSetup.pdb
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 3 libraries
USER32, SHELL32, KERNEL32
Exports 0 functions
Resources 7 Resources
Sections 5 Sections

Version Information

CompanyName HHD Software Ltd.
FileDescription Hex Editor Neo Setup Package
FileVersion 7.50.04.8813
LegalCopyright © 2001 - 2023 by HHD Software Ltd. All rights reserved.
InternalName setup.exe
OriginalFilename setup.exe
ProductName Hex Editor Neo
ProductVersion 7.50.04.8813
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 69,815 bytes 70,144 bytes 6.78 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7DC3014DC9F6E788F7EF7665AF32A0F9
.rdata 0x00013000 23,630 bytes 24,064 bytes 4.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6CA73BB295F368D5556FCD1B8B1D72B3
.data 0x00019000 12,704 bytes 2,048 bytes 1.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 70D0BD2DA1BEC62BB857AC4F9227DFDD
.rsrc 0x0001d000 30,036 bytes 30,208 bytes 7.22 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 061D14B2E7443C41DD9E3EAABFDF3DDF
.reloc 0x00025000 445,440 bytes 445,440 bytes 7.82 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 33E33DCAF61CF2362D3A66C7A11BDE84
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 7 (29,580 bytes)
Resource Type Count Total Size Percentage
RT_ICON 4 28,297 bytes
95.7%
RT_GROUP_ICON 1 62 bytes
0.2%
RT_VERSION 1 840 bytes
2.8%
RT_MANIFEST 1 381 bytes
1.3%

Certificate Chain Analysis

Certificate Information
Product Hex Editor Neo
Description Hex Editor Neo Setup Package
File Version 7.50.04.8813
Original Name setup.exe
Signing Date 07:58 AM 02/26/2025 (101 days ago)
Verification Status The digital signature of the object did not verify.
Signers HHD SOFTWARE LIMITED; GlobalSign GCC R45 CodeSigning CA 2020; GlobalSign Code Signing Root R45; GlobalSign; GlobalSign Root CA - R1
Counter Signers Globalsign TSA for Advanced - G4 - 202311; GlobalSign Timestamping CA - SHA384 - G4; GlobalSign Root CA - R6
Internal Name setup.exe
Copyright © 2001 - 2023 by HHD Software Ltd. All rights reserved.
Certificate Chain Summary
GlobalSign #1 Primary
Validity Period: 2018-09-19 00:00:00 → 2028-01-28 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 01 EE 5F 16 9D FF 97 35 2B 64 65 D6 6A
GlobalSign Code Signing Root R45 #2 Chain
Validity Period: 2020-07-28 00:00:00 → 2029-03-18 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 78 03 18 42 45 70 8A 41 CF 6F 01 B8 EE B4 A9 54
GlobalSign GCC R45 CodeSigning CA 2020 #3 Chain
Validity Period: 2020-07-28 00:00:00 → 2030-07-28 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 77 BD 0E 03 A1 B7 08 F8 54 AB 06 72 10 D9 04 47
HHD SOFTWARE LIMITED #4 Chain
Validity Period: 2023-03-27 12:38:58 → 2026-06-23 12:38:58
Signature Algorithm: sha256RSA
Serial Number: 04 F3 0E 3D A6 CD 84 CD 8F 88 F6 C8
Globalsign TSA for Advanced - G4 - 202311 #5 Chain
Validity Period: 2023-11-02 10:30:02 → 2034-12-04 10:30:02
Signature Algorithm: sha256RSA
Serial Number: 01 19 75 74 71 C9 92 D7 44 DF A5 96 EB B9 70 15
GlobalSign Timestamping CA - SHA384 - G4 #6 Chain
Validity Period: 2018-06-20 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 01 EC 1C 92 40 DE FD 2E 40 5D 7C 47 74
GlobalSign #7 Chain
Validity Period: 2014-12-10 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 45 E6 BB 03 83 33 C3 85 65 48 E6 FF 45 51

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
9 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware