Gridinsoft Logo
File Icon

The 金荣后台.exe (Host Process for Push Router Client of OMA-DM Setup) File Analysis

Technical Analysis

File Name 金荣后台.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
98304:lp4xzsWxHXSYsnagOr0IRbdkgF95fAg8DaO8c9qcUqni:2RSkdHXW+E4cUq
Scanner Version 1.0.218.174
Database Version 2025-06-14 12:00:21 UTC

Suspicious File Detected

Detected by 30 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
42%
Detection Rate
4,198,400
File Size (bytes)
30/72
Engines Detected
2025-06-14
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
9c2d4803afa5d1bca41e3f6a7c23be41
SHA1
af806a7642fe4c9ccfabfad687f24133909a655c
SHA256
b3d47b4f900bb49c6cdab88dcd6bb822588c239869110d9e42f14e16dbfadbb3
SHA512
f0acbd60be78feef224aca05f4f9875f9e7f69ad876b5d7425514c857a29d5ac42a10a54bdec616ee9f7e9d9721e6f135cfffb10c24e2846efbf0e9468494926
ImpHash
a57a5b9a255d5cd24dfdb0ed27c5248f

Security Engines with Detections (30 of 72)

Bkav
W32.AIDetectMalware Malicious
AVG
Win64:MalwareX-gen [Bd] Malicious
Elastic
malicious (high confidence) Malicious
Skyhigh
BehavesLike.Win32.Generic.rc Malicious
Cylance
Unsafe Malicious
Sangfor
Suspicious.Win32.Save.ins Malicious
CrowdStrike
win/malicious_confidence_70% (D) Malicious
K7GW
Trojan ( 005246d51 ) Malicious
K7AntiVirus
Trojan ( 005246d51 ) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of Win32/Packed.FlyStudio.AA potentially unwanted Malicious
Cynet
Malicious (score: 100) Malicious
APEX
Malicious Malicious
Avast
Win64:MalwareX-gen [Bd] Malicious
McAfeeD
Real Protect-LS!9C2D4803AFA5 Malicious
Trapmine
malicious.high.ml.score Malicious
Sophos
Generic ML PUA (PUA) Malicious
Ikarus
Trojan.Win32 Malicious
GData
Win32.Trojan.PSE.17UBEGE Malicious
Varist
W32/OnlineGames.HG.gen!Eldorado Malicious
Antiy-AVL
RiskWare/Win32.FlyStudio.a Malicious
Xcitium
Worm.Win32.Dropper.RA@1qraug Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
Google
Detected Malicious
AhnLab-V3
Dropper/Win32.Agent.C121380 Malicious
Malwarebytes
Generic.Malware.AI.DDS Malicious
TrendMicro-HouseCall
Trojan.Win32.VSX.PE04C9Z Malicious
SentinelOne
Static AI - Malicious PE Malicious
MaxSecure
Trojan.Malware.121218.susgen Malicious
DeepInstinct
MALICIOUS Malicious
42 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 77afaf4aae55a4ef7cf25b47fb1900c7
Fuzzy: 80de128c36f749bb72f073061eafb48f
dHash: c860f14c4862b9cc
Image Base 0x00400000
Entry Point 0x0045d884
Compilation Time 2025-06-04 11:18:39
Checksum 0x00000000 (Actual: 0x0040bb24)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 12 libraries
Exports 0 functions
Resources 55 Resources
Sections 4 Sections

Version Information

Comments This installation was built with Inno Setup.
CompanyName
FileDescription Host Process for Push Router Client of OMA-DM Setup
FileVersion
LegalCopyright
OriginalFileName
ProductName Host Process for Push Router Client of OMA-DM
ProductVersion 10.0.14393.0
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 505,434 bytes 507,904 bytes 6.58 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ FD46D8FB9059A171B77A0AFE4C291898
.rdata 0x0007d000 3,584,560 bytes 3,588,096 bytes 7.82 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6914760ADE4F92442202611913F9EDDD
.data 0x003e9000 225,642 bytes 73,728 bytes 5.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2F28218D9FC654CBA34DF4DD2D7CD606
.rsrc 0x00421000 24,576 bytes 24,576 bytes 4.55 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A821611F2F5638FBE74B2D76124244A2
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 55 (20,119 bytes)
Resource Type Count Total Size Percentage
TEXTINCLUDE 3 370 bytes
1.8%
RT_CURSOR 4 1,104 bytes
5.5%
RT_BITMAP 14 6,040 bytes
30%
RT_ICON 3 3,256 bytes
16.2%
RT_MENU 2 656 bytes
3.3%
RT_DIALOG 10 4,418 bytes
22%
RT_STRING 11 2,268 bytes
11.3%
RT_GROUP_CURSOR 3 74 bytes
0.4%
RT_GROUP_ICON 3 60 bytes
0.3%
RT_VERSION 1 1,412 bytes
7%
RT_MANIFEST 1 461 bytes
2.3%

Certificate Chain Analysis

Certificate Information
Product Host Process for Push Router Client of OMA-DM
Description Host Process for Push Router Client of OMA-DM Setup
Certificate Chain Summary
Microsoft Corporation #1 Primary
Validity Period: 2024-08-22 19:25:57 → 2025-07-05 19:25:57
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 05 A6 58 10 67 4B 3D 6C 7C F6 00 00 00 00 05 A6
Microsoft Code Signing PCA 2010 #2 Chain
Validity Period: 2010-07-06 20:40:17 → 2025-07-06 20:50:17
Signature Algorithm: sha256RSA
Serial Number: 61 0C 52 4C 00 00 00 00 00 03
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2024-07-25 18:31:06 → 2025-10-22 18:31:06
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 F7 58 20 75 04 CA FB C2 F4 00 01 00 00 01 F7
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
Microsoft Corporation #5 Chain
Validity Period: 2024-08-22 19:26:43 → 2025-08-20 19:26:43
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 03 FD 36 44 39 73 0D DC 02 28 00 00 00 00 03 FD
Microsoft Code Signing PCA 2011 #6 Chain
Validity Period: 2011-07-08 20:59:09 → 2026-07-08 21:09:09
Signature Algorithm: sha256RSA
Serial Number: 61 0E 90 D2 00 00 00 00 00 03
Microsoft Time-Stamp Service #7 Chain
Validity Period: 2024-07-25 18:31:11 → 2025-10-22 18:31:11
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 FA FB 3B 44 D3 77 33 C6 D3 00 01 00 00 01 FA

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
30 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware