Gridinsoft Logo
File Icon

The WinRAR.exe (WinRAR) File Analysis

Technical Analysis

File Name WinRAR.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.217.174
Database Version 2025-05-30 23:00:17 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,312,272
File Size (bytes)
2025-05-31
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
2e5422a3b00ff9625c867c796552fa6d
SHA1
a8c954087acee2b4eaea9619b382a4c071cd854e
SHA256
a1c7ffe4fdad4da4066df44d12a356517a0505e7b1e6fa9c4b08f02c513aa142
SHA512
bdc83cc3ae08666bc1ea5cbaa6168e5f094d8b818700810ec24b7817df96d6f2c0d4d4f43d3bc841775a2998ee856ba7ac6395b8ab93d9d0ee461819e03d6cfc
ImpHash
c262f2646fa5ea1b86da29604e53baa7

PE Analysis

Basic Information

Icon
Hash: b3f0266a9874e070b3ec855645687948
Fuzzy: 33d9200afee9550e4e551841fda604a1
dHash: b233333a6b3a3230
Image Base 0x140000000
Entry Point 0x1401c5a10
Compilation Time 2025-03-20 10:00:20
Checksum 0x003330a2 (Actual: 0x003330a2)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path d:\Projects\WinRAR\build\winrar64\Release\WinRAR.pdb
Digital Signature OK
Imports 14 libraries
Exports 0 functions
Resources 359 Resources
Sections 7 Sections

Version Information

ProductName WinRAR
CompanyName Alexander Roshal
FileDescription WinRAR
FileVersion 7.11.0
ProductVersion 7.11.0
InternalName WinRAR
LegalCopyright Copyright © Alexander Roshal 1993-2025
OriginalFilename WinRAR.exe
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,024,110 bytes 2,024,448 bytes 6.54 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BD418C8AF69F05D0E86CEBECFD1EAC38
.rdata 0x001f0000 328,658 bytes 328,704 bytes 5.75 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E53CA92C82B97A65B8F15F7C59C1FD48
.data 0x00241000 358,620 bytes 45,056 bytes 4.55 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 428116356EE46FE320812E6DCE5C0B91
.pdata 0x00299000 52,896 bytes 53,248 bytes 6.18 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BA5123DB9BE96652F357836E65C70C33
.didat 0x002a6000 304 bytes 512 bytes 2.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C30BB356F9BA6DCFF76290FCF4ED78B3
.rsrc 0x002a7000 841,136 bytes 841,216 bytes 7.15 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3F0DF78F098BD686A680AD5405F80BD0
.reloc 0x00375000 7,660 bytes 7,680 bytes 5.38 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 793E31E6301713E360117C103C55FAED
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 359 (820,513 bytes)
Resource Type Count Total Size Percentage
PNG 111 432,314 bytes
52.7%
RT_CURSOR 2 1,128 bytes
0.1%
RT_ICON 46 273,645 bytes
33.4%
RT_MENU 2 3,478 bytes
0.4%
RT_DIALOG 83 70,616 bytes
8.6%
RT_STRING 100 35,506 bytes
4.3%
RT_ACCELERATOR 6 544 bytes
0.1%
RT_GROUP_CURSOR 1 34 bytes
0%
RT_GROUP_ICON 6 680 bytes
0.1%
RT_VERSION 1 720 bytes
0.1%
RT_MANIFEST 1 1,848 bytes
0.2%

Certificate Chain Analysis

Certificate Information
Product WinRAR
Description WinRAR
File Version 7.11.0
Original Name WinRAR.exe
Signing Date 10:01 AM 03/20/2025 (118 days ago)
Verification Status Signed
Signers win.rar GmbH; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Internal Name WinRAR
Copyright Copyright © Alexander Roshal 1993-2025
Certificate Chain Summary
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #1 Primary
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
win.rar GmbH #2 Chain
Validity Period: 2023-08-08 00:00:00 → 2026-08-07 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 04 8B 08 39 9E C7 03 62 3C 72 CD 20 77 AD 65 D9
DigiCert Timestamp 2024 #3 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #4 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware