Gridinsoft Logo
File Icon

The c7bfc86cdf71b800b82d70ddee1ea57f51abeab07c70842c39a137cc0fe369bb.exe File Analysis

Technical Analysis

File Name c7bfc86cdf71b800b82d70ddee1ea57f51abeab07c70842c39a137cc0fe369bb.exe
File Type
Win32 EXE
Magic Bytes MS-DOS executable PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
196608:IABkO+zyBwMAET/qV2Jsv6tWKFdu9CeMl1:IABGh0/q4Jsv6tWKFdu9CTl1
Scanner Version 1.0.225.174
Database Version 2025-09-20 03:00:37 UTC

Suspicious File Detected

Detected by 15 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
21%
Detection Rate
11,469,168
File Size (bytes)
15/71
Engines Detected
2025-09-20
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
99a1025b3d45090a791a6b24349f621f
SHA1
2ecff3d48a074b4770442a2b535a5b2e59e0914b
SHA256
c7bfc86cdf71b800b82d70ddee1ea57f51abeab07c70842c39a137cc0fe369bb
SHA512
8d7cd0741dfd650392fb382a62693a93be2f63b3f586026ed3c3b47f464936cc3d9b22202d0aff1c37d952ca713bcf56351f3738830a8f0075433196f37d367d
ImpHash
43ee94db28e374b12051085efeaa02a1

Security Engines with Detections (15 of 71)

huorong
Trojan/Injector.cib Malicious
Symantec
Trojan Horse Malicious
Kaspersky
Trojan.Win32.PoolInject.cgq Malicious
Avast
Win64:MalwareX-gen [Trj] Malicious
Rising
Trojan.Injector!8.C4 (CLOUD) Malicious
McAfeeD
ti!C7BFC86CDF71 Malicious
Trapmine
malicious.high.ml.score Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
GData
Win64.Trojan.Agent.IN4H3L Malicious
Kingsoft
Win32.Trojan.PoolInject.a Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
Tencent
Win32.Backdoor.Phish.Jkjl Malicious
TrellixENS
Artemis!99A1025B3D45 Malicious
AVG
Win64:MalwareX-gen [Trj] Malicious
DeepInstinct
MALICIOUS Malicious
56 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 56bf19144e9127370a15917aacf46c59
Fuzzy: 405fea7613cd55b2865e12c9db212a92
dHash: b2e0a496b2da6a66
Image Base 0x140000000
Entry Point 0x14058bdec
Compilation Time 1970-01-01 00:00:00
Checksum 0x00000000 (Actual: 0x00af4b70)
OS Version 0.0
PEiD Signatures MS-DOS executable PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 20 libraries
Exports 0 functions
Resources 2 Resources
Sections 6 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,841,102 bytes 6,841,344 bytes 5.93 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9C46DB501B7AEB8C3BD1C0FD4D8F648A
.rdata 0x00688000 4,022,258 bytes 4,022,272 bytes 5.78 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7F5B20075EC21ECD33D9A8F74AC7A05A
.data 0x00a5e000 427,672 bytes 198,144 bytes 4.55 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C0D2F8A2FF9358A058A29A17068C9FBF
.pdata 0x00ac7000 391,008 bytes 391,168 bytes 6.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5CDF817A0A99FF76F766AA80A46425D0
_RDATA 0x00b27000 244 bytes 512 bytes 2.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D5976EFE0EFF0A04712DEAD08DBBA52A
.rsrc 0x00b28000 2,400 bytes 2,560 bytes 4.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7C98DBED8C946617943C792C76A3C16C

Resource Analysis

Total Resources: 2 (2,236 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 2,216 bytes
99.1%
RT_GROUP_ICON 1 20 bytes
0.9%

Certificate Chain Analysis

Certificate Information
Signing Date 09:52 AM 02/20/2024 (690 days ago)
Verification Status The digital signature of the object did not verify.
Signers Beijing Yincaishijiao Technology Co., Ltd; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2023; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Certificate Chain Summary
DigiCert Trusted Root G4 #1 Primary
Validity Period: 2013-08-01 12:00:00 → 2038-01-15 12:00:00
Signature Algorithm: sha384RSA
Serial Number: 05 9B 1B 57 9E 8E 21 32 E2 39 07 BD A7 77 75 5C
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #2 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
Beijing Yincaishijiao Technology Co., Ltd #3 Chain
Validity Period: 2022-04-25 00:00:00 → 2025-05-20 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 03 CA DF 0C 5D B1 0F 74 EB D7 C6 E2 60 52 8A B9
DigiCert Timestamp 2023 #4 Chain
Validity Period: 2023-07-14 00:00:00 → 2034-10-13 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 05 44 AF F3 94 9D 08 39 A6 BF DB 3F 5F E5 61 16
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #5 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #6 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
15 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware