Gridinsoft Logo
File Icon

The airshipper.exe (Provides automatic updates for the voxel RPG Veloren.) File Analysis

Technical Analysis

File Name airshipper.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.213.174
Database Version 2025-04-13 22:00:32 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
59,272,014
File Size (bytes)
2025-04-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
1f484997c594717516cfd71c695fe226
SHA1
685ddd9d24b4f4017ced67569339fb1d9021850f
SHA256
af340a12777a0df2f601d9fa7069ba8781a0297683e1da3099f0b20b8a3d20b7
SHA512
4911e48f90c0e915e8478b1844c0dd1090c623607e8698519a536cf757f64ad5ce03382b778d9816638bacb12c633dea4466885e44132840c71ecd65db8f26b1
ImpHash
0325ce35b16205487c48e1c130200c40

PE Analysis

Basic Information

Icon
Hash: d8f19d79b628d2134d03d74b7a1e4e1b
Fuzzy: bb57a45fffc9d6a20d6680cb9e6a8f8a
dHash: d2eccce8a8b2d4cc
Image Base 0x140000000
Entry Point 0x140001410
Compilation Time 2024-12-28 17:54:40
Checksum 0x03892025 (Actual: 0x03892025)
OS Version 4.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 21 libraries
Exports 0 functions
Resources 7 Resources
Sections 24 Sections

Version Information

FileDescription Provides automatic updates for the voxel RPG Veloren.
ProductName airshipper
ProductVersion 0.16.0
FileVersion 0.16.0
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 15,146,600 bytes 15,147,008 bytes 6.23 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ A5FCA8EE386EBBC40A2DD25DD6B0C435
.data 0x00e73000 16,880 bytes 16,896 bytes 2.72 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A13CC8EE1E2CD0B8964884C269DF8395
.rdata 0x00e78000 19,157,200 bytes 19,157,504 bytes 6.79 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6D257993BFB3B7CD8FF189752868A191
.pdata 0x020be000 158,148 bytes 158,208 bytes 6.65 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 28EFCE3DABE78A8A648DCEBC6514D13C
.xdata 0x020e5000 238,364 bytes 238,592 bytes 5.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5822D858CA180ACFA519341B2874EADC
.bss 0x02120000 10,336 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x02123000 15,044 bytes 15,360 bytes 4.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FCE135BE9370D1C955DDB56FA8F30FDA
.CRT 0x02127000 120 bytes 512 bytes 0.54 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CF9B4E499EC21D8F285A7E340FF5C602
.tls 0x02128000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x02129000 67,752 bytes 68,096 bytes 7.27 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6EE5C2E16D5A17EC85215AD14F8EA4F3
.reloc 0x0213a000 122,688 bytes 122,880 bytes 5.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A109A3A68EF1F57851B809A77E8B0BA2
/4 0x02158000 5,536 bytes 5,632 bytes 2.82 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ CBF642F98566D74697A6069B8EC8CA45
/19 0x0215a000 4,516,599 bytes 4,516,864 bytes 5.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7667E6584D01675E34F9303A21950A07
/35 0x025a9000 5,241,333 bytes 5,241,344 bytes 5.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A68433980E57DB885B7D0796268939E6
/47 0x02aa9000 20,941 bytes 20,992 bytes 4.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ DB8198EB89FF95776A27EAC84AE664A6
/61 0x02aaf000 1,886,049 bytes 1,886,208 bytes 6.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ F5C0FED06592742554FF1BDB3EBB6D8E
/73 0x02c7c000 9,104 bytes 9,216 bytes 4.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A121954FBC584B48A7F402C2D9E78F4E
/86 0x02c7f000 6,731,301 bytes 6,731,776 bytes 5.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 84446A69DD7A6FFCDE17842317A6B0AF
/97 0x032eb000 720 bytes 1,024 bytes 2.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 1CE611C9E3759C98E7AB187DA3271529
/113 0x032ec000 2,276,864 bytes 2,276,864 bytes 2.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 1568257F71949F6B9A49D6516340F906
/127 0x03518000 18,069 bytes 18,432 bytes 4.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 40028CDEC183141E7F1DE28F3F41960A
/143 0x0351d000 1,146,524 bytes 1,146,880 bytes 5.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ AA34E00D026AE36C115F054F4F239035
/159 0x03635000 429,017 bytes 429,056 bytes 5.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 0ED655395ADA20B077975390D85330F3
/172 0x0369e000 47,672 bytes 48,128 bytes 5.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 38397C3722A2C1D23298BC3A44113408
Entropy Analysis Alert

3 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 7 (67,316 bytes)
Resource Type Count Total Size Percentage
RT_ICON 5 66,716 bytes
99.1%
RT_GROUP_ICON 1 76 bytes
0.1%
RT_VERSION 1 524 bytes
0.8%

Certificate Chain Analysis

Certificate Information
Product airshipper
Description Provides automatic updates for the voxel RPG Veloren.
File Version 0.16.0

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware