File Name | wireguard-installer.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-22 15:00:31 UTC |
Malware family: Quasar
Hash Type | Value | Action |
---|---|---|
MD5 |
1cf9257c07936d7fbf508dc113e9b6d5
|
|
SHA1 |
324f8a1f0779fe42baabc544bc7f6814a3d150ca
|
|
SHA256 |
eeee2b0a6ad1c7e4614fed4dfbe58b63776f6a3a6758267b5a976b4dc4315f48
|
|
SHA512 |
081fa75e73138fb403aa01cb09f3051b7ee6954ab0a15366016cabe873d7a64f8374c85d9bcdf068fa019930419c818d102063983a5547ae5107773fe25e5c12
|
|
ImpHash |
5c900c91f80fa7e4541847a2f04d55bd
|
Icon |
Hash: 7d276439d9810323502f89b8e46d1edd
Fuzzy: 89745e05fcc1193c9e6f7bd2da24eeea dHash: f0f261edec6c98f0 |
Image Base | 0x00400000 |
Entry Point | 0x00401110 |
Compilation Time | 2022-01-06 16:16:06 |
Checksum | 0x0002368b (Actual: 0x0002368b) |
OS Version | 6.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports |
3 libraries
KERNEL32, ntdll, msvcrt |
Exports | 0 functions |
Resources | 6 Resources |
Sections | 6 Sections |
CompanyName | WireGuard LLC |
FileDescription | WireGuard Installer: Fast, Modern, Secure VPN Tunnel |
FileVersion | 1.0 |
InternalName | wireguard-installer |
LegalCopyright | Copyright © 2015-2022 Jason A. Donenfeld <[email protected]>. All Rights Reserved. |
OriginalFilename | wireguard-installer.exe |
ProductName | WireGuard |
ProductVersion | 1.0 |
Comments | https://www.wireguard.com/ |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
37,002 bytes | 37,376 bytes | 6.35 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
EA03A25A29A9A835AE3B79C8BD6C8E53 |
.rdata |
0x0000b000 |
7,002 bytes | 7,168 bytes | 5.68 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8EA340AE1985338508E101B4750D7130 |
.data |
0x0000d000 |
17,704 bytes | 512 bytes | 2.14 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
FBED440F2BE0D95CD06B86B838B6F022 |
.tls |
0x00012000 |
8 bytes | 512 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BF619EAC0CDF3F68D496EA9344137E8B |
.rsrc |
0x00013000 |
25,536 bytes | 25,600 bytes | 5.58 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0A204F9B335CC1FB8F5BC1E4695DFC52 |
.reloc |
0x0001a000 |
1,580 bytes | 2,048 bytes | 5.69 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
BA58008E0872561DF08DB7B816FB44C8 |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 3 | 22,328 bytes | |
RT_GROUP_ICON | 1 | 48 bytes | |
RT_VERSION | 1 | 1,004 bytes | |
RT_MANIFEST | 1 | 1,745 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Backdoor.Win32.Quasar.tr without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system