Gridinsoft Logo

The Revolution-3.0-011125.exe File Analysis

Technical Analysis

File Name Revolution-3.0-011125.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.228.174
Database Version 2025-11-06 14:00:30 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
80,831,488
File Size (bytes)
2025-11-06
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0d5ea00968e9eb4557174fe516662b25
SHA1
c5fc8fb68611ad1fbd72c06abb11ae6630f45a0d
SHA256
ac21420e0b36855b3e6cdfe2acad573110f38918d1a35113f0468fbf005a618b
SHA512
cff1fc957a86618cacbee38b165ce7be361c544bb45efe7fb7c41b94eda7bf28058a8839d31f88f0271c1d68b7dbb95f1a76c25ee27030ace7c392e61d8bb11e
ImpHash
f80fda1f25527e965dfe1de9dbd31a90

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x14004fd10
Compilation Time 2025-11-02 16:41:32
Checksum 0x00000000 (Actual: 0x04d1a959)
OS Version 6.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 14 libraries
Exports 0 functions
Resources 0 Resources
Sections 15 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,168,438 bytes 1,168,896 bytes 6.45 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C1A2A8FE1036A478C6998E6851D4EBD2
.rdata 0x0011f000 242,292 bytes 242,688 bytes 5.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DDC8F424F2557906C9B341C076180AF5
.buildid 0x0015b000 53 bytes 512 bytes 0.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FFEC97B1E95D10BEBCADDE10E6C76F5B
.data 0x0015c000 2,636,984 bytes 2,048 bytes 2.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 878DF0BD9BB092F8B15A4522D5FBC668
.pdata 0x003e0000 31,956 bytes 32,256 bytes 6.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D2B6B93CDD0A075A3137CD8A71E5DA74
.rodata 0x003e8000 78,394,144 bytes 78,394,368 bytes 6.73 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1D6DA82BFAD89ADE9219BDB1F138D653
.tls 0x04eac000 1,232 bytes 1,536 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 53E979547D8C2EA86560AC45DE08AE25
.reloc 0x04ead000 8,532 bytes 8,704 bytes 5.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ FA630314C2AD4CED16617E0674C8A2BE
/4 0x04eb0000 20,828 bytes 20,992 bytes 4.69 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ F530923E896FF03C172D824DC1FFF404
/18 0x04eb6000 48 bytes 512 bytes 0.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7A90115A111FA200FA3A2F140109A647
/58 0x04eb7000 102,779 bytes 102,912 bytes 5.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 85EB1FEE5B21B5D8DE2F3ED996E62CEE
/70 0x04ed1000 68,394 bytes 68,608 bytes 5.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 35F428019814F4CD750B914E7C6C95B8
/82 0x04ee2000 186,016 bytes 186,368 bytes 2.79 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 4B7782092A57582D011996DB9AFDCE2C
/33 0x04f10000 13,008 bytes 13,312 bytes 1.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D3D9E5110D56CFD41228269101806AE1
/47 0x04f14000 40,429 bytes 40,448 bytes 5.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ CF3A7AC02DBAB1C3EA9DE2B3EEB946F9
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware