File Name | DependencyCore_94812.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-12 04:00:42 UTC |
Malware family: Snackarcin
Hash Type | Value | Action |
---|---|---|
MD5 |
0094fe3d542571751a93ef23ab850c0f
|
|
SHA1 |
b09476c9cf2aa72a2eb571ca1367b2157b82b4dd
|
|
SHA256 |
b9a8dfeec3b2cdcc519ab31b7aa84e15f87f37163289cae7444968b2d936bc3b
|
|
SHA512 |
d3cc1cc9908cdec30ea84cd17b717d9c413c8d868d66a1e6d4b32ca49d7ef276b6911f2cdf1c8c20804eff66f1c2cf7829510b162a2a4bab7134b32e4c62bc40
|
|
ImpHash |
7d354937719f012ff63291d74e707fdb
|
Icon |
Hash: 9444da76f58f480c32690dc4a694343d
Fuzzy: 797e4ccc8616cb455e9cb4660db66123 dHash: 34f4ccfcfcd4f0e0 |
Image Base | 0x00400000 |
Entry Point | 0x0052c270 |
Compilation Time | 2025-03-06 18:58:56 |
Checksum | 0x00670688 (Actual: 0x00670688) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports | 11 libraries |
Exports | 0 functions |
Resources | 15 Resources |
Sections | 7 Sections |
FileDescription | NanaZip Self Extracting Executable (Setup) |
FileVersion | 5.0.1283.0 |
InternalName | NanaZip.Core.Sfx.Setup |
LegalCopyright | © M2-Team and Contributors. All rights reserved. |
OriginalFilename | NanaZip.Core.Setup.sfx |
ProductName | NanaZip |
ProductVersion | 5.0.1283.0 |
Translation | 0x0000 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
1,304,442 bytes | 1,304,576 bytes | 5.88 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
046104F5E812C5FDB649F1EBCE4A1BDC |
.rdata |
0x00140000 |
80,044 bytes | 80,384 bytes | 5.09 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
3CDCA1CE9707551CCDBFABC9871779A0 |
.data |
0x00154000 |
611,336 bytes | 585,216 bytes | 7.99 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
38846CC6E89CDFC0A093090A246FB090 |
.detourc |
0x001ea000 |
4,512 bytes | 4,608 bytes | 2.72 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
08DAA666AD563F7DF7BCC5945F2C899C |
.detourd |
0x001ec000 |
12 bytes | 512 bytes | 0.07 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1D7D80E8B5CE8C86E7C833467964B6AE |
.rsrc |
0x001ed000 |
76,416 bytes | 76,800 bytes | 6.12 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A41D1B464709C5DC3FAD710B8442D633 |
.reloc |
0x00200000 |
24,504 bytes | 24,576 bytes | 6.57 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
E75E6B4E04AD7A5C379D2BADC84141B6 |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 8 | 72,827 bytes | |
RT_DIALOG | 1 | 144 bytes | |
RT_STRING | 3 | 232 bytes | |
RT_GROUP_ICON | 1 | 118 bytes | |
RT_VERSION | 1 | 816 bytes | |
RT_MANIFEST | 1 | 1,379 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Malware.Win32.Snackarcin.bot without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system