Gridinsoft Logo
File Icon

The ecos-dhub-ratter-win.exe (Node.js JavaScript Runtime) File Analysis

Technical Analysis

File Name ecos-dhub-ratter-win.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.142.174
Database Version 2023-10-11 16:04:42 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
63,848,876
File Size (bytes)
2023-10-11
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
58a375ddb704b0276229ebc7ab4a1883
SHA1
69781fcb488e40a4be5d6652854f1f410205d34c
SHA256
bf98ed9f11287725a0aee62192eb6a515b0107d34d2bdd1bb64a6cfc59d2dc99
SHA512
83452f43c976364e6989086cbd5007bf655360c62221d215a1bced985d0238ed8496029bc353c6fd0d20d74ee93049b6a26027cbf98307d11124535f0c0ed2a2
ImpHash
4d0fb8dc9ee470058274f448bebbb85f

PE Analysis

Basic Information

Icon
Hash: 5b68da4010f12363d151f409ceb33d34
Fuzzy: e487424e8b5cee3808f28e6462b06171
dHash: 70f8bcf8f8f2f070
Image Base 0x140000000
Entry Point 0x14125e198
Compilation Time 2022-07-08 23:42:38
Checksum 0x00000000 (Actual: 0x03ce86ca)
OS Version 6.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
PDB Path C:\Users\runneradmin\AppData\Local\Temp\pkg.24e0b2b2d51e47b9dba34c30\node\out\Release\node.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 11 libraries
Exports 17255 functions
Resources 9 Resources
Sections 7 Sections

Version Information

CompanyName Node.js
ProductName Node.js
FileDescription Node.js JavaScript Runtime
FileVersion 18.5.0
ProductVersion 18.5.0
OriginalFilename node.exe
InternalName node
LegalCopyright Copyright Node.js contributors. MIT license.
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 19,570,560 bytes 19,570,688 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ A68BF38C27F1C9777E7256DBF52A2E32
.rdata 0x012ab000 16,669,688 bytes 16,669,696 bytes 6.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 70CD9E529D08852F47CB84DBF355B24B
.data 0x02291000 2,983,884 bytes 141,312 bytes 3.86 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE EC94C9183EEEA0A1DEE0F4E89CA6F8D7
.pdata 0x0256a000 917,196 bytes 917,504 bytes 6.80 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9E7C8D93702D4532DB1795A99911A4B0
_RDATA 0x0264a000 244 bytes 512 bytes 2.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ ECB4BBE56E47C45A2388A28F6B547D3A
.rsrc 0x0264b000 141,944 bytes 142,336 bytes 6.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DB6ED472B000243688D70FC984344BE5
.reloc 0x0266e000 131,572 bytes 131,584 bytes 5.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D5809755CA5D408E8A1E4C3932B51246
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 9 (141,386 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 139,730 bytes
98.8%
RT_GROUP_ICON 1 90 bytes
0.1%
RT_VERSION 1 744 bytes
0.5%
RT_MANIFEST 1 822 bytes
0.6%

Certificate Chain Analysis

Certificate Information
Product Node.js
Description Node.js JavaScript Runtime
File Version 18.5.0
Original Name node.exe
Internal Name node
Copyright Copyright Node.js contributors. MIT license.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware