Gridinsoft Logo
File Icon

The LDPlayer9_ru_1007_ld.exe (LDPlayer) File Analysis

Technical Analysis

File Name LDPlayer9_ru_1007_ld.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
98304:waMOOH01Z71vVOO+svd2YJVr5cOlprwwEGK579UbrGim:waMOA01uCtf5copnEGKF97D
Scanner Version 1.0.171.174
Database Version 2024-04-11 15:00:27 UTC

Suspicious File Detected

Detected by 3 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
4%
Detection Rate
6,550,768
File Size (bytes)
3/72
Engines Detected
2024-04-11
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6bb66e3d87545f31c0bbd832ec25d5f2
SHA1
177ad92140c75dc5ca2b62bc0720f3a259a1f6f3
SHA256
ecfeedaf64f5cb7d43dffb5a07488356a05355e4dcacf3d55887abaa8b6557ac
SHA512
df3474d40e63d86e23a887be0c3297cff314b3b2ad9e31029e5b466da39aa86b47f821cba1d280110d76c34cc2ffad82b1edebf9e91e56a9c7c87bf794b27a0c
ImpHash
43a01e9edfe7a53d6e88d675117126c6

Security Engines with Detections (3 of 72)

Malwarebytes
PUP.Optional.ChinAd Malicious
ESET-NOD32
a variant of Win32/DNDownloader.B potentially unwanted Malicious
Webroot
W32.Deceptor.Ld.Player Malicious
69 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 8462a99ffa1b282cc7c67cd11645172f
Fuzzy: d741995a72279a7f7cf2833cdc40d038
dHash: f08c96232b9b8bf4
Image Base 0x00400000
Entry Point 0x004de5d9
Compilation Time 2023-05-29 03:57:01
Checksum 0x006499a9 (Actual: 0x006499a9)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path H:\trunk_en_4.0(多捆绑)\downloader2\bin\ldplayerinst.pdb
Digital Signature OK
Imports 18 libraries
Exports 0 functions
Resources 36 Resources
Sections 5 Sections

Version Information

CompanyName XUANZHI CO., LIMITED
FileDescription LDPlayer
FileVersion 1.0.0
InternalName ldinst.exe
LegalCopyright Copyright (C) 2016
OriginalFilename ldinst.exe
ProductName LDPlayer
ProductVersion 1.0.0
Translation 0x0404 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,156,428 bytes 1,156,608 bytes 6.56 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 1CF78147176B3C864F7714E41DD2BDD0
.rdata 0x0011c000 286,942 bytes 287,232 bytes 5.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E56ABBB0E3AB62E7D97FE37114089D2A
.data 0x00163000 63,368 bytes 24,576 bytes 4.86 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9C2304CC6CDC4C39FADB15FFD7371CAF
.rsrc 0x00173000 4,996,800 bytes 4,997,120 bytes 7.81 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 362F9DB0E9C3688E068080A3907C3E6C
.reloc 0x00637000 62,800 bytes 62,976 bytes 6.63 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 797F02934A09E296FFB25A6C118568F9
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 36 (4,994,800 bytes)
Resource Type Count Total Size Percentage
TXT 3 51,142 bytes
1%
ZIPRES 1 4,348,371 bytes
87.1%
RT_ICON 26 593,472 bytes
11.9%
RT_STRING 1 76 bytes
0%
RT_ACCELERATOR 1 16 bytes
0%
RT_GROUP_ICON 2 376 bytes
0%
RT_VERSION 1 696 bytes
0%
RT_MANIFEST 1 651 bytes
0%

Certificate Chain Analysis

Certificate Information
Product LDPlayer
Description LDPlayer
File Version 1.0.0
Original Name ldinst.exe
Signing Date 03:57 AM 05/29/2023 (797 days ago)
Verification Status Signed
Signers Shanghai Chang Zhi Network Technology Co,. Ltd.; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2022 - 2; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Internal Name ldinst.exe
Copyright Copyright (C) 2016
Certificate Chain Summary
DigiCert Trusted Root G4 #1 Primary
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #2 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #3 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
DigiCert Timestamp 2022 - 2 #4 Chain
Validity Period: 2022-09-21 00:00:00 → 2033-11-21 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0C 4D 69 72 4B 94 FA 3C 2A 4A 3D 29 07 80 3D 5A
Shanghai Chang Zhi Network Technology Co,. Ltd. #5 Chain
Validity Period: 2021-11-24 00:00:00 → 2024-11-26 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0D 65 08 23 68 F9 43 30 12 3C 9A 85 3A 2F DE BF

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
3 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware