Gridinsoft Logo

The ea2310a0916222097eef511a9c220696545ded9a (Microsoft® HTML Help Executable) File Analysis

Technical Analysis

File Name ea2310a0916222097eef511a9c220696545ded9a
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
24576:NfaicdIfRzYculNC8wnCxNxCNS4sPiuINC8wnCxNxCNS4sPiu:Nyic4IlVnxN0o5RIVnxN0o5R
Scanner Version 1.0.213.174
Database Version 2025-04-11 11:00:24 UTC

Suspicious File Detected

Detected by 19 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
26%
Detection Rate
1,274,368
File Size (bytes)
19/72
Engines Detected
2025-04-11
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
51deb881a4b0e162e1fa708a94aa95e8
SHA1
ea2310a0916222097eef511a9c220696545ded9a
SHA256
da2ac071b7655c95ae6e1ac00751d75a83f9bd59e24e88f15e3298b3b00a7da4
SHA512
a80564a490175f7bcb827287d0f983858db4f48a1dac2eda25bcbeaa2866a0371c4449b5c145b56c7e577074ecaca385bbf7444285b052bdb749cdc840c524a8
ImpHash
8d36bf26f0c905ea57ae9a0cd9daeb1f

Security Engines with Detections (19 of 72)

Bkav
W64.AIDetectMalware Malicious
Elastic
malicious (high confidence) Malicious
Skyhigh
BehavesLike.Win64.VirusWinExpiro.tc Malicious
Cylance
Unsafe Malicious
CrowdStrike
win/malicious_confidence_100% (D) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
ESET-NOD32
a variant of Win64/GenKryptik.HICP Malicious
APEX
Malicious Malicious
TrendMicro-HouseCall
Trojan.Win32.VSX.PE04C9V Malicious
Kaspersky
VHO:Trojan-PSW.Win32.Stealer.gen Malicious
Avast
Win64:MalwareX-gen [Misc] Malicious
McAfeeD
ti!DA2AC071B765 Malicious
Sophos
Generic ML PUA (PUA) Malicious
Google
Detected Malicious
Varist
W64/Agent.NGBH Malicious
Microsoft
Program:Win32/Wacapew.C!ml Malicious
Malwarebytes
Crypt.Trojan.MSIL.DDS Malicious
AVG
Win64:MalwareX-gen [Misc] Malicious
DeepInstinct
MALICIOUS Malicious
53 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140056fd0
Compilation Time 2025-04-10 13:45:36
Checksum 0x0013c8fa (Actual: 0x0013c8fa)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 1 libraries
KERNEL32
Exports 0 functions
Resources 2 Resources
Sections 13 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft® HTML Help Executable
FileVersion 10.0.19041.1 (WinBuild.160101.0800)
InternalName HH 1.41
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename HH.exe
ProductName HTML Help
ProductVersion 10.0.19041.1
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 439,264 bytes 439,296 bytes 7.04 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 856674C7362BAF4BF41F229CFE987B8B
.rdata 0x0006d000 54,332 bytes 54,784 bytes 4.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BA6795AA1279CCEFFD0E8F047EA9AE20
.data 0x0007b000 19,648 bytes 7,680 bytes 3.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7C85A17FB784FE6F397150069871FB2F
.pdata 0x00080000 9,108 bytes 9,216 bytes 5.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EF082F027341B094064BF10EC39D745F
.B1 0x00083000 12,681 bytes 12,800 bytes 6.93 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 421999C7ABC1F89751ADE89DC80117D7
.gxfg 0x00087000 5,072 bytes 5,120 bytes 5.09 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0F50877259F3E1D724E40A01840F78C1
.retplne 0x00089000 140 bytes 512 bytes 1.05 (Normal) 0x00000000 8C950F651287CBC1296BCB4E8CD7E990
.tls 0x0008a000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
_RDATA 0x0008b000 500 bytes 512 bytes 4.19 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 10ED36D4878EC48A9A922C9EFEDA769E
.reloc 0x0008c000 2,240 bytes 2,560 bytes 5.17 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ FA9187FE079A8E2D1112C0D63AE13C0D
.jss 0x0008d000 368,640 bytes 368,640 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 62E27A042A1B4795713063759C3DBC47
.jss 0x000e7000 368,640 bytes 368,640 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 62E27A042A1B4795713063759C3DBC47
.rsrc 0x00141000 1,995 bytes 2,048 bytes 4.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D4010E7F0191BDC8AB3A562A43C88EE1
Entropy Analysis Alert

2 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 2 (1,835 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 868 bytes
47.3%
RT_MANIFEST 1 967 bytes
52.7%

Certificate Chain Analysis

Certificate Information
Product HTML Help
Description Microsoft® HTML Help Executable
File Version 10.0.19041.1 (WinBuild.160101.0800)
Original Name HH.exe
Internal Name HH 1.41
Copyright © Microsoft Corporation. All rights reserved.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
19 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware