Gridinsoft Logo
File Icon

The Netherworld Covenant.exe File Analysis

Technical Analysis

File Name Netherworld Covenant.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.218.174
Database Version 2025-06-21 11:00:31 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
3,745,280
File Size (bytes)
2025-06-21
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c8534388db55d949db3f5dfdd3468cd8
SHA1
b2c3943d7cd892473cf9930bac5a47d3bdefb5dc
SHA256
fec1dfcb68395ec58d728489fe0b2a2b87426afe56d016502c32fea41c1d5fb9
SHA512
a45d2a91c535e9935a257f374a0d9f868113adff4f8c2d10de5867e8f78028676b69f6cb14933223fd4abbffc1a7139d7a225403c369ea4dada85d359b27dabe
ImpHash
4bec1f56b28ab6a6614f6734e69744ca

PE Analysis

Basic Information

Icon
Hash: b2f7aa9db1af11c80904f4bffa894344
Fuzzy: ad1427dfa07f960454264249f978c934
dHash: 03431e1e0e37330f
Image Base 0x140000000
Entry Point 0x140f5fb68
Compilation Time 2025-04-08 14:33:48
Checksum 0x00000000 (Actual: 0x00399a0c)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 9 libraries
kernel32, user32, advapi32, oleaut32, gdi32, shell32, version, ole32, UnityPlayer
Exports 2 functions
Resources 12 Resources
Sections 10 Sections

Version Information

FileVersion 2022.3.61.7099371
LegalCopyright (c) 2005-2025 Unity Technologies. All rights reserved.
ProductVersion 2022.3.61f1 (6c53ebaf375d)
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 53,248 bytes 30,208 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 263A72BFE5612F0512936343093BB413
0x0000e000 40,960 bytes 14,848 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E252DDF54AFE88BD075E6E76490EABC1
0x00018000 8,192 bytes 512 bytes 6.69 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1FA9EB05BF0D71CD5D433CBAF57B8A5F
0x0001a000 4,096 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x0001b000 4,096 bytes 512 bytes 1.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 48186E9D72FDE555AA02BECDA9908048
0x0001c000 569,344 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x000a7000 4,096 bytes 1,536 bytes 7.09 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 873259D052244EDBF009A2963FCCFB2E
.rsrc 0x000a8000 569,344 bytes 565,760 bytes 5.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B524ECD1B7FFDE256A29F2E927E4680A
0x00133000 12,021,760 bytes 280,064 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2E46B6960A1198EA7759597BFF8AF9F8
0x00caa000 2,850,816 bytes 2,850,816 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F83F3B1D6C96085EBEC3DF3585A3C75F
Entropy Analysis Alert

4 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 12 (564,957 bytes)
Resource Type Count Total Size Percentage
RT_ICON 9 562,568 bytes
99.6%
RT_GROUP_ICON 1 132 bytes
0%
RT_VERSION 1 528 bytes
0.1%
RT_MANIFEST 1 1,729 bytes
0.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware