File Name | 1568877722716_1568877722.torrent-2648160.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
|
Scanner Version | 1.0.207.174 |
Database Version | 2025-02-06 23:00:36 UTC |
Malware family: Downloader
Hash Type | Value | Action |
---|---|---|
MD5 |
9595e49300c884ea972200f03d7551aa
|
|
SHA1 |
32266d5316e4a71037304a73b71970e422d0c4c7
|
|
SHA256 |
a4c8b95638e736bfd4cabdf43121ebb65229c3754a2bb35ffe9a81a8091c2d16
|
|
SHA512 |
137b8559d7e4e0f2a11b97a2caacc6f466f62a136c0f3f36e5d65b6dabdad073fb7eb32805b26951aa0328a6958731fb2a80b9e2f063a3a3d0b0d44feddd6915
|
|
ImpHash |
2afd616a4b0219c3ec513cb740eeaa50
|
Icon |
Hash: 0f987f19e45db2ed607e6ec3bdeeb1e4
Fuzzy: 1d0f20672c0549081dff295b8ddb6e73 dHash: 43b2cc4d160f4d33 |
Image Base | 0x00400000 |
Entry Point | 0x01e72060 |
Compilation Time | 2022-09-01 16:51:11 |
Checksum | 0x008a6c07 (Actual: 0x008a6c07) |
OS Version | 5.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
|
Digital Signature | OK |
Imports | 22 libraries |
Exports | 0 functions |
Resources | 355 Resources |
Sections | 3 Sections |
CompanyName | uFiler.pro |
FileVersion | 2022.2.0.0 |
OriginalFilename | uFiler.exe |
ProductName | uFiler |
ProductVersion | 1.0.0 |
ProgramID | com.embarcadero.uFiler |
FileDescription | uFiler |
Translation | 0x0409 0x04e4 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
UPX0 |
0x00001000 |
18,833,408 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
UPX1 |
0x011f7000 |
8,896,512 bytes | 8,893,952 bytes | 7.94 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9AFDD5EE46A902D164136F412D689157 |
.rsrc |
0x01a73000 |
131,072 bytes | 130,048 bytes | 4.37 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D3E5BFCE9D7AAC86D2F5C372EA52273F |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
UNICODEDATA | 6 | 191,535 bytes | |
VCLSTYLE | 1 | 96,382 bytes | |
RT_CURSOR | 23 | 11,484 bytes | |
RT_BITMAP | 35 | 48,834 bytes | |
RT_ICON | 7 | 103,160 bytes | |
RT_STRING | 108 | 134,916 bytes | |
RT_RCDATA | 148 | 10,406,271 bytes | |
RT_GROUP_CURSOR | 23 | 460 bytes | |
RT_GROUP_ICON | 2 | 110 bytes | |
RT_VERSION | 1 | 624 bytes | |
RT_MANIFEST | 1 | 1,751 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Risk.Win32.Downloader.dd!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system