Gridinsoft Logo
File Icon

The Panicore-Online-Steam.exe File Analysis

Technical Analysis

File Name Panicore-Online-Steam.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
24576:LeRz2pFX1dEEAT4LP1c/bUO0S+f8Ir7wYBb9AY5/8Oy:zRPswO+EIrsYL98Oy
Scanner Version 1.0.183.174
Database Version 2024-08-01 10:00:28 UTC

Suspicious File Detected

Detected by 16 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
22%
Detection Rate
853,961
File Size (bytes)
16/73
Engines Detected
2024-08-01
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
5111da8f5f80f637b5cad1d26c32d61f
SHA1
5b8ed7fdce3bd1588749b0b6cbc8c1a5ae4fe170
SHA256
c5dbd8ab88cb8ba05b2a9072b4e93a68b8ce7b74f6f46d29bb155d1cf466162c
SHA512
2e996abd6b1e858fb6ac24251f3e4315e358d06268ebd88b2f9258b1cb3c5c787d5d067098ac4d7fcf227373eb06ec54ec797e1d6354dc0e2c66ed27c6ae1707
ImpHash
aac51396886833dc961fcd7aab7711e4

Security Engines with Detections (16 of 73)

FireEye
Generic.mg.5111da8f5f80f637 Malicious
Skyhigh
BehavesLike.Win32.Generic.cc Malicious
McAfee
Artemis!5111DA8F5F80 Malicious
Zillya
Trojan.Generic.Win32.1688925 Malicious
Paloalto
generic.ml Malicious
Elastic
malicious (high confidence) Malicious
APEX
Malicious Malicious
ClamAV
Win.Dropper.Nanocore-9986456-0 Malicious
Sophos
Generic ML PUA (PUA) Malicious
Webroot
W32.Adware.Gen Malicious
Google
Detected Malicious
Varist
W32/ABRisk.OWNM-9013 Malicious
Cynet
Malicious (score: 100) Malicious
Cylance
Unsafe Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/malicious_confidence_90% (D) Malicious
57 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 8d9da329386d64d6b86a12bd2f986399
Fuzzy: 9043363bfee17e0d508057b9ae7189e9
dHash: 84b4b4d4c4ccccc0
Image Base 0x00400000
Entry Point 0x00420600
Compilation Time 2023-01-24 16:13:30
Checksum 0x00000000 (Actual: 0x000ddb13)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 3 libraries
KERNEL32, OLEAUT32, gdiplus
Exports 0 functions
Resources 27 Resources
Sections 6 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 207,932 bytes 208,384 bytes 6.70 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ FC608A53FE3E601715F37FD1C9608D71
.rdata 0x00034000 45,360 bytes 45,568 bytes 5.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4DA0020BC0F2D972B38E9D84C33442AD
.data 0x00040000 149,328 bytes 4,608 bytes 4.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 029158C7AF186150865DE52086FB6948
.didat 0x00065000 400 bytes 512 bytes 3.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F699AC0448DE7C6EB3A68B92109FB04F
.rsrc 0x00066000 57,412 bytes 57,856 bytes 6.80 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8C1C2141FE156B0185A4D4AC5ACE237E
.reloc 0x00075000 9,132 bytes 9,216 bytes 6.65 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8FEA45FE908999929CF403A6E794A37A
Entropy Analysis Alert

3 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 27 (55,782 bytes)
Resource Type Count Total Size Percentage
PNG 2 8,430 bytes
15.1%
RT_ICON 7 38,113 bytes
68.3%
RT_DIALOG 6 2,958 bytes
5.3%
RT_STRING 10 4,302 bytes
7.7%
RT_GROUP_ICON 1 104 bytes
0.2%
RT_MANIFEST 1 1,875 bytes
3.4%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
16 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware