File Name | HMC 2.2.0.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.222.174 |
Database Version | 2025-07-29 10:00:15 UTC |
Malware family: XOREncoded
Hash Type | Value | Action |
---|---|---|
MD5 |
91f0d7fd8fdc2f4324ee39521abc3ee5
|
|
SHA1 |
d2931fcd0e1bbab22e6d70b07373a9eca82a8771
|
|
SHA256 |
f261687e56606a7d258c5b1b03e8d6d8f147ac2b396fb58d9e2679804a369248
|
|
SHA512 |
c78cee1e22b5ce3233e92ee7ba702a095a1a2c1dbd509ab37066b3a56626156714be41ef776366b50d991abcde4a07bfd1b77f827a704d45092d8ea534f7e345
|
|
ImpHash |
96ba4c3dc31425783f668f28c5ddeb97
|
Icon |
Hash: 6827a0cd015535db0f9f43f40e65b039
Fuzzy: 73e9f9fdcaee90524191ede728c1d29d dHash: 71ccccc8c4cccc71 |
Image Base | 0x00400000 |
Entry Point | 0x00401551 |
Compilation Time | 2025-07-15 13:44:53 |
Checksum | 0x0053a61d (Actual: 0x0053a61d) |
OS Version | 5.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | No valid SignedData structure was found. |
Imports |
2 libraries
SHELL32, KERNEL32 |
Exports | 0 functions |
Resources | 10 Resources |
Sections | 5 Sections |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
17,900 bytes | 17,920 bytes | 6.53 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
DC099FEDBA97FCF04924E2F64CE686E0 |
.rdata |
0x00006000 |
8,250 bytes | 8,704 bytes | 4.59 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
1A0B29F606E89AD8901A3039122020ED |
.data |
0x00009000 |
5,122,304 bytes | 5,118,976 bytes | 7.31 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
8DA2EC6CCB6305ED2B911A74251D2062 |
.reloc |
0x004ec000 |
11,112 bytes | 11,264 bytes | 1.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
E3D9589CCE5BEA396BA376D0D88143C2 |
.rsrc |
0x004ef000 |
305,124 bytes | 305,152 bytes | 4.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
94AECAB489E27C184A5F902F036433A3 |
2 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 9 | 304,414 bytes | |
RT_GROUP_ICON | 1 | 132 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Susp.U.XOREncoded.sd!yf without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system