File Name | KRX Client.exe |
File Type |
Win32 EXE
|
Magic Bytes | PE32+ executable (GUI) x86-64, for MS Windows |
SSDEEP Hash |
393216:43w8auifT198n6ym8VXtyjQamaWfKNiLtYy7Hn:JnuuB9uP9zaWCgLHH
|
Scanner Version | 1.0.217.174 |
Database Version | 2025-05-28 02:00:13 UTC |
Detected by 13 security engines - requires caution
Hash Type | Value | Action |
---|---|---|
MD5 |
83345dcf858e72495b399a6ada63771b
|
|
SHA1 |
8123de63ddff8ae6a776ea509d9a63552857bb0c
|
|
SHA256 |
d461de6b36bb439363d3bfd474640a3940172e02bc793ac70e89ce9f3374d1f3
|
|
SHA512 |
7ebe8f87407cd3d88d082819fa8460cebb844d3a3c39457ba98994b7a7bb28cf0535b80cc1ae148d427f877971e0ebdb9e865ce2ec4c1a2223ba4bfc0cb4dce7
|
|
ImpHash |
3681815b6e014bd03113ae1c7d152bf0
|
Icon |
Hash: b2d83ddb1f424edec7b61dd0342e6ef5
Fuzzy: 42b4a0cd7cb12abe88397e0661bbd678 dHash: 0071e84cf82a86f0 |
Image Base | 0x140000000 |
Entry Point | 0x141b22058 |
Compilation Time | 2025-05-25 19:05:23 |
Checksum | 0x0100831b (Actual: 0x0100831b) |
OS Version | 6.0 |
PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
Digital Signature | No valid SignedData structure was found. |
Imports | 26 libraries |
Exports | 0 functions |
Resources | 7 Resources |
Sections | 13 Sections |
Comments | DDNet |
CompanyName | DDNet Team |
FileDescription | DDNet |
FileVersion | 19.2 |
InternalName | DDNet |
LegalCopyright | Copyright (C) DDNet Team |
OriginalFilename | DDNet.exe |
ProductName | DDNet |
ProductVersion | 19.2 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
|
0x00001000 |
3,535,784 bytes | 1,584,640 bytes | 7.98 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
FF49A06AC1CD73BAA55EF215F3EACCD3 |
|
0x00361000 |
1,316,132 bytes | 430,080 bytes | 7.97 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
10F7657D37EB78CFAC8CCD8D4662B76B |
|
0x004a3000 |
620,096 bytes | 46,592 bytes | 7.96 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6DB0D0D8437772C6D3B31B7BF19F3A28 |
|
0x0053b000 |
112,596 bytes | 66,560 bytes | 7.70 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
F4DA5A502BB6CA0AE0D1E3ECF762407C |
|
0x00557000 |
256 bytes | 512 bytes | 0.10 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
DBC9ADF0E711C55AA7120AA5BED2C861 |
|
0x00558000 |
33,944 bytes | 23,040 bytes | 7.94 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
EE7AFE9A41FB6619A10001DAA31F6651 |
|
0x00561000 |
29,760 bytes | 6,656 bytes | 7.85 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
29079A24ED94726C922F922C9110AF71 |
.idata |
0x00569000 |
4,096 bytes | 2,048 bytes | 3.73 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
FC91D9995E9DB85D6D48F176A69BBC8A |
.tls |
0x0056a000 |
4,096 bytes | 512 bytes | 0.38 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
681D3DE9B435A8FB1FACDC710354CCB3 |
.rsrc |
0x0056b000 |
34,304 bytes | 34,304 bytes | 6.33 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8C136BE4F01CA7F63CC7578D965B41DD |
.pdata |
0x00574000 |
22,732,800 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.boot |
0x01b22000 |
14,572,544 bytes | 14,572,544 bytes | 7.95 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B73CE7F8CA763FA87AF3185B1504E935 |
.reloc |
0x02908000 |
4,096 bytes | 16 bytes | 2.55 (Normal) |
IMAGE_SCN_MEM_READ
|
4D7399C4CBEEBAB53C46B7E33F0A618B |
7 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 4 | 31,083 bytes | |
RT_GROUP_ICON | 1 | 62 bytes | |
RT_VERSION | 1 | 692 bytes | |
RT_MANIFEST | 1 | 1,632 bytes |
Product | DDNet |
Description | DDNet |
File Version | 19.2 |
Original Name | DDNet.exe |
Internal Name | DDNet |
Copyright | Copyright (C) DDNet Team |
✓ This file has been digitally signed and the certificate chain has been verified
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important