File Name | Volcano executor_08488193.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.217.174 |
Database Version | 2025-06-05 03:00:31 UTC |
Malware family: InstallCore
Hash Type | Value | Action |
---|---|---|
MD5 |
688165a01a09bf0a274df49a074ca7af
|
|
SHA1 |
ba2e194e9bd592f11913b1bea3ca7c7be4521f5d
|
|
SHA256 |
c7791778f6329f2ee70db33a77f9b33edac40e8c87e6e243405711361761a01f
|
|
SHA512 |
a21202b6d596a7ac1a6286b9382ee91219d48ac38f715ab48dd8520cb30506f18778d4c68ef9ecc84f8c34b69983b89fb753ee908abfb518482a682fe4ed9f30
|
|
ImpHash |
5d2faf47bf3bd0a1d7cb2819751593ce
|
Icon |
Hash: 9369138d09d205577211b0f34212a165
Fuzzy: c98f96d6ffe5af8d4eb0870c1dc20826 dHash: b2e0b496a6cada72 |
Image Base | 0x00400000 |
Entry Point | 0x007989ba |
Compilation Time | 2025-05-27 11:09:23 |
Checksum | 0x005c5107 (Actual: 0x005c5107) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports | 19 libraries |
Exports | 0 functions |
Resources | 9 Resources |
Sections | 5 Sections |
FileDescription | Manager |
FileVersion | 1 |
InternalName | Manager |
LegalCopyright | Manager |
OriginalFilename | Manager |
ProductName | Manager |
ProductVersion | 1 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
4,351,531 bytes | 4,352,000 bytes | 6.64 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E0ECB9C5F4AF4182CC78BB17B8AA486C |
.rdata |
0x00428000 |
1,085,430 bytes | 1,085,440 bytes | 5.63 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D12940B5B1069CF861F152216DBA6FB9 |
.data |
0x00531000 |
175,652 bytes | 149,504 bytes | 4.86 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
F3E8DBD93184AD1FA2C6F9A8E9D6512C |
.rsrc |
0x0055c000 |
103,416 bytes | 103,424 bytes | 3.17 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A7E9C251F2BA7F12280232710C89CBE7 |
.reloc |
0x00576000 |
310,140 bytes | 310,272 bytes | 6.59 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
85AD394E35E5367FA20BF1FFAF8B69C7 |
2 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 6 | 101,643 bytes | |
RT_GROUP_ICON | 1 | 90 bytes | |
RT_VERSION | 1 | 556 bytes | |
RT_MANIFEST | 1 | 562 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Adware.Win32.InstallCore.vl!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system