Gridinsoft Logo

The hh.exe File Analysis

Technical Analysis

File Name hh.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.217.174
Database Version 2025-06-07 15:00:24 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
400,256
File Size (bytes)
2025-06-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
4e50a2038e5559b93acb930f7de85657
SHA1
d00de140412a8d970d5bb677b223837acef8ee9d
SHA256
f168ae9ebf1c17f7f72554540e40f2a132cf1f490ce1b49ca6e0cc7db81c5372
SHA512
31dad1f0e01a9b6889e4e24b53fc73f277ad36ce771da05c2dee87ea03296111f4eed583ade50638aa7186effe9b0cb6681d4fcfe92d93538f313092a777b877
ImpHash
b18f73f929533462fe490e44b8a6973e

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1400013f0
Compilation Time 2025-06-07 12:08:21
Checksum 0x0006c214 (Actual: 0x0006c214)
OS Version 4.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 2 libraries
KERNEL32, msvcrt
Exports 0 functions
Resources 2 Resources
Sections 19 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,368 bytes 6,656 bytes 5.87 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ A69A846A981C056E0D142F0737E54FFD
.data 0x00003000 128 bytes 512 bytes 0.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 21185AB306B150711A8F4571F9F1F2E6
.rdata 0x00004000 2,344 bytes 2,560 bytes 3.95 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D0244C2FC409CCCE691A693DEAFDA166
.pdata 0x00005000 540 bytes 1,024 bytes 2.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 669ADD040F2D7A5C239B05686A35719E
.xdata 0x00006000 408 bytes 512 bytes 3.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3E622AAFF37AADC04A4502AEC9369AD9
.bss 0x00007000 384 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x00008000 1,640 bytes 2,048 bytes 3.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 29A30FB8D02DC7C10C461633FE5AD87C
.tls 0x00009000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0000a000 284,352 bytes 284,672 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 78B137D2B9EA18B3BB345972620B3942
.reloc 0x00050000 104 bytes 512 bytes 1.35 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ AF7C684B5C05322054E2D363EE93C19F
/4 0x00051000 1,040 bytes 1,536 bytes 1.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ F91D91DF1188C2242B526F22A6644A57
/19 0x00052000 39,798 bytes 39,936 bytes 5.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7754B3ADBA4C82714EBF82DD1BCBB9CF
/31 0x0005c000 7,177 bytes 7,680 bytes 4.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ C8877FDD09A5C9324162CE9ED596F07B
/45 0x0005e000 7,065 bytes 7,168 bytes 4.89 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ E8DC0A10BA57EFAFFE04A439852816F7
/57 0x00060000 2,032 bytes 2,048 bytes 4.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 888ABCFCF20FE18B005303E5373D16DD
/70 0x00061000 707 bytes 1,024 bytes 3.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ DBAA2ADF62FAA5FBE5D8255C67238D2B
/81 0x00062000 3,640 bytes 4,096 bytes 4.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 0671F1D02717222F79703A42102CA809
/97 0x00063000 4,604 bytes 4,608 bytes 5.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5DCDC13D957D0AB7F5C1D945E6020787
/113 0x00065000 405 bytes 512 bytes 4.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A009753C265146998D9DF0F793FA87C8
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 2 (284,155 bytes)
Resource Type Count Total Size Percentage
RT_RCDATA 2 284,155 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware