File Name | AcrossSetup_2_30b.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.178.174 |
Database Version | 2024-06-08 03:01:04 UTC |
Malware family: Redline
Hash Type | Value | Action |
---|---|---|
MD5 |
013259e6c32bac59938e30086e88d27b
|
|
SHA1 |
0edd41ec07d23608e3106e1f7bad485431ea9254
|
|
SHA256 |
bb69aa08bdbcaa8860d26feaa036760b683f0e164fb18b5a772f0c4321e63b1d
|
|
SHA512 |
c5737f95aa15829c1fe433c92c9c837bb0c372e9c6863c6dd1cfbb80be3d6d9532196c7ef5992e29e3ab70918b395934bc4b5961c44845ccd5ceec858479d479
|
|
ImpHash |
bc70c4fa605f17c85050b7c7b6d42e44
|
Icon |
Hash: 18406f799bfc9ee737c69028fe1c0734
Fuzzy: e555e06a276978c32ed8efbc4ad0084c dHash: b269ccaaaacc69b2 |
Image Base | 0x00400000 |
Entry Point | 0x004067cc |
Compilation Time | 2013-10-14 05:50:27 |
Checksum | 0x0470bf45 (Actual: 0x0470bf45) |
OS Version | 6.3 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | wextract.pdb |
Digital Signature | OK |
Imports |
8 libraries
ADVAPI32, KERNEL32, GDI32, USER32, msvcrt, COMCTL32, Cabinet, VERSION |
Exports | 0 functions |
Resources | 49 Resources |
Sections | 5 Sections |
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.9600.16428 (winblue_gdr.131013-1700) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.9600.16428 |
Translation | 0x0409 0x04b0 |
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.9600.16428 (winblue_gdr.131013-1700) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.9600.16428 |
Translation | 0x0412 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
26,060 bytes | 26,112 bytes | 6.38 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E9BF1A1E456A9A811B1B86E6602E3636 |
.data |
0x00008000 |
6,796 bytes | 1,024 bytes | 3.18 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
317F8A934EE443EEE01C2A315BDE9CA1 |
.idata |
0x0000a000 |
4,216 bytes | 4,608 bytes | 5.05 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D8675BA112EF922C6057A02546757A1A |
.rsrc |
0x0000c000 |
74,433,683 bytes | 74,434,048 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
F7C465D24427C50AE31214587BDC76C5 |
.reloc |
0x04709000 |
5,038 bytes | 5,120 bytes | 3.72 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
83DE2F9B2C95BE6FEA06BCED7E8A058E |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
AVI | 1 | 11,802 bytes | |
RT_ICON | 6 | 105,829 bytes | |
RT_DIALOG | 12 | 4,552 bytes | |
RT_STRING | 12 | 9,694 bytes | |
RT_RCDATA | 14 | 74,295,532 bytes | |
RT_GROUP_ICON | 1 | 90 bytes | |
RT_VERSION | 2 | 2,104 bytes | |
RT_MANIFEST | 1 | 1,511 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Spy.Win32.Redline.lu!heur without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system