Gridinsoft Logo
File Icon

The Potassium.exe (Potassium) File Analysis

Technical Analysis

File Name Potassium.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
196608:yypcOkyIBA+fBR1FWEOzp7lSn00KJNTTH1/Q+K3QCJG5nU4NEDC07M9:yypcH3Ai14EW7lS3KfTmFACJGBU4nP
Scanner Version 1.0.251.174
Database Version 2026-08-12 17:00:30 UTC

Suspicious File Detected

Detected by 2 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
3%
Detection Rate
25,086,464
File Size (bytes)
2/70
Engines Detected
2026-08-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
2bfb8df7baeb371440bf440257597b44
SHA1
880241dae0058f349a8ad3c187e5c363f7dd94fc
SHA256
d4a06aed70cfddaf747e6d2564bed581d4686d854d4771b199ef1ec6c7b3dfbd
SHA512
a0bb1296ec97c33d396bb30881291b8a9e4048b2fb84fa770c06454c17e5825c2a5dbfa9141c538316a3c182b20854652cdad390245a9c42ebeb77fea2ce0e12
ImpHash
0a4c4ab481a59f774f0142feb249460d

Security Engines with Detections (2 of 70)

Trapmine
malicious.high.ml.score Malicious
Microsoft
Program:Win32/Contebrew.A!ml Malicious
68 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: e60a5533d04dfaefafc65bcf9911ec54
Fuzzy: 5f1056e3ea0715b75a116d24d9c97bb8
dHash: 4db3e0e4d878334f
Image Base 0x140000000
Entry Point 0x140e14080
Compilation Time 2026-08-07 20:30:44
Checksum 0x00000000 (Actual: 0x017f5d20)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path Potassium.pdb
Digital Signature No valid SignedData structure was found.
Imports 28 libraries
Exports 0 functions
Resources 13 Resources
Sections 6 Sections

Version Information

CompanyName pot
FileDescription Potassium
FileVersion 1.0.7
ProductName Potassium
ProductVersion 1.0.7
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 14,990,951 bytes 14,991,360 bytes 6.25 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 04B4250035BC7B202D412C7B503D982A
.rdata 0x00e4d000 9,055,744 bytes 9,055,744 bytes 7.05 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DAA1325A4028EAC0DAE81C725EFDB065
.data 0x016f0000 45,936 bytes 35,328 bytes 3.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D7AF223743DB58D40AEFA0D7E07708DA
.pdata 0x016fc000 836,592 bytes 836,608 bytes 6.82 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1DED1D35A3E069E34E2DB8E37FF83F92
.rsrc 0x017c9000 113,376 bytes 113,664 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9E5C9D3B413EDC51BA01ADB2832909AE
.reloc 0x017e5000 52,592 bytes 52,736 bytes 5.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ AFA27D451DFD22B36627836748A80124
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 13 (112,606 bytes)
Resource Type Count Total Size Percentage
RT_ICON 10 111,447 bytes
99%
RT_GROUP_ICON 1 146 bytes
0.1%
RT_VERSION 1 464 bytes
0.4%
RT_MANIFEST 1 549 bytes
0.5%

Certificate Chain Analysis

Certificate Information
Product Potassium
Description Potassium
File Version 1.0.7

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
2 security engines flagged this file. Could be a real threat, or could be a false alarm — common with keygens, game trainers, and legitimate system utilities. Check if the file has a valid digital signature and whether it came from the official source.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware