The dopus exe (Directory Opus) GP Software File Malware Analysis
Gridinsoft Logo
File Icon

The dopus.exe (Directory Opus) File Analysis

Technical Analysis

File Name dopus.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.228.174
Database Version 2025-10-23 11:00:19 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
35,471,776
File Size (bytes)
2025-10-23
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
53212b1975d871034558fbf33c30a694
SHA1
1caa9d6f71142adf8aa8448add50b61baa872327
SHA256
ab2b46c7c200b3efa1c80239b8b7dd34e49c60f9ed7e7569a3fb7bc30dfff8fc
SHA512
f8e342d2557a675cd0eeff7f31b3a858d90b1883ecdcb6f1281df6baa950bf9f688a3ed88bcbb8e46ec93e8a8c751c2a80357ed3f5ce1b4f13f5894022651448
ImpHash
7d7e3ce413f74b0cf08a38a8472e3bd3

PE Analysis

Basic Information

Icon
Hash: 2ef27c43109284d442f71b39ab233342
Fuzzy: 62c2328dca86660f2a0298734e58412e
dHash: 78ecfedacad46421
Image Base 0x140000000
Entry Point 0x1401966d0
Compilation Time 2025-08-25 02:07:18
Checksum 0x021db4ea (Actual: 0x021db4cc)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path dopus.pdb
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 2 libraries
COMCTL32, KERNEL32
Exports 234 functions
Resources 512 Resources
Sections 9 Sections

Version Information

CompanyName GP Software
FileDescription Directory Opus
FileVersion 13.18.0.0
InternalName dopus
LegalCopyright Copyright © 1999-2025 GP Software
LegalTrademarks Directory Opus, Opus, DOpus, DirOpus, OpusPC, PCOpus are trademarks of GP Software
OriginalFilename dopus.exe
ProductName Directory Opus
ProductVersion 13.18.0.0
Translation 0x0c09 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 22,658,068 bytes 22,658,560 bytes 6.41 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2157021E04A3F033FFD0D0088084718C
.rdata 0x0159d000 4,814,186 bytes 4,814,336 bytes 6.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ ADEE4EC8E845FF35D23AA37C0FF53D49
.data 0x01a35000 866,068 bytes 566,272 bytes 4.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 56D79F7EBEE0C0F28CEA6CFDAF1020DE
.pdata 0x01b09000 700,980 bytes 701,440 bytes 6.73 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E39A2AD9C18F4FD8069D4CCF94649B79
.fptable 0x01bb5000 256 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.detourc 0x01bb6000 8,656 bytes 8,704 bytes 2.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D56D13D9409B13E7261EAC8172C31A0D
.detourd 0x01bb9000 24 bytes 512 bytes 0.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 083338860205EFCC4D20E102CFE79C12
.rsrc 0x01bba000 6,568,400 bytes 6,568,448 bytes 6.69 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D29C729D4E51DDBBDFC2309CF40D4164
.reloc 0x021fe000 140,260 bytes 140,288 bytes 5.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 62AA4BB1F9FFD2EFEF669885C78642CC
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 512 (6,541,433 bytes)
Resource Type Count Total Size Percentage
BIN 6 297,092 bytes
4.5%
JPG 1 32,248 bytes
0.5%
PNG 176 3,559,972 bytes
54.4%
WAV 1 30,030 bytes
0.5%
XML 7 119,245 bytes
1.8%
ZIP 1 22 bytes
0%
RT_CURSOR 97 1,624,364 bytes
24.8%
RT_BITMAP 3 296 bytes
0%
RT_ICON 152 868,186 bytes
13.3%
RT_DIALOG 3 3,176 bytes
0%
RT_GROUP_CURSOR 26 1,514 bytes
0%
RT_GROUP_ICON 37 2,350 bytes
0%
RT_VERSION 1 936 bytes
0%
RT_MANIFEST 1 2,002 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Directory Opus
Description Directory Opus
File Version 13.18.0.0
Original Name dopus.exe
Signing Date 02:07 AM 08/25/2025 (62 days ago)
Verification Status The digital signature of the object did not verify.
Signers GP Software (Redbrook Pty Ltd); Sectigo Public Code Signing CA EV R36; Sectigo Public Code Signing Root R46; Sectigo (AAA)
Counter Signers DigiCert SHA256 RSA4096 Timestamp Responder 2025 1; DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1; DigiCert Trusted Root G4; DigiCert
Internal Name dopus
Copyright Copyright © 1999-2025 GP Software
Certificate Chain Summary
Sectigo Public Code Signing Root R46 #1 Primary
Validity Period: 2021-05-25 00:00:00 → 2028-12-31 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
Sectigo Public Code Signing CA EV R36 #2 Chain
Validity Period: 2021-03-22 00:00:00 → 2036-03-21 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 33 D7 08 A8 91 40 53 19 E2 A5 BB D3 39 B9 AD 6E
GP Software (Redbrook Pty Ltd) #3 Chain
Validity Period: 2023-11-07 00:00:00 → 2026-11-06 23:59:59
Signature Algorithm: sha256RSA
Serial Number: C9 B2 09 3F 1C 34 89 36 43 DA A1 AD 1C C9 78 68
DigiCert SHA256 RSA4096 Timestamp Responder 2025 1 #4 Chain
Validity Period: 2025-06-04 00:00:00 → 2036-09-03 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0A 80 EF 18 4B 8D F1 05 82 D1 C4 76 A7 95 74 68
DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1 #5 Chain
Validity Period: 2025-05-07 00:00:00 → 2038-01-14 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0D C7 AC 57 05 FF 21 99 2E 40 43 22 0C 3A 49 86
DigiCert Trusted Root G4 #6 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware