×
This file seems to be a .NET executable .
Sadly, Manalyzer's analysis techniques were designed for native code, so it's likely that this report won't tell you much.
Sorry!
Architecture
IMAGE_FILE_MACHINE_I386
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date
2021-Sep-20 20:18:53
Comments
Update
CompanyName
GitHub
FileDescription
Update
FileVersion
1.1.1.0
InternalName
Update.exe
LegalCopyright
Copyright © GitHub 2013-2015
LegalTrademarks
OriginalFilename
Update.exe
ProductName
Update
ProductVersion
1.1.1.0
Assembly Version
1.1.1.0
Info
Matching compiler(s):
Microsoft Visual C# v7.0 / Basic .NET
Suspicious
Strings found in the binary may indicate undesirable behavior:
Contains another PE executable:
This program cannot be run in DOS mode.
Contains domain names:
api.github.com
github.com
go.microsoft.com
http://go.microsoft.com
http://go.microsoft.com/fwlink/?LinkID
http://go.microsoft.com/fwlink/?LinkId
http://schemas.microsoft.com
http://schemas.microsoft.com/XML-Document-Transform
http://schemas.microsoft.com/packaging/2010/07/
http://schemas.microsoft.com/packaging/2010/07/manifest
http://schemas.microsoft.com/packaging/2010/07/nuspec.xsd
http://schemas.microsoft.com/packaging/2011/08/nuspec.xsd
http://schemas.microsoft.com/packaging/2011/10/nuspec.xsd
http://schemas.microsoft.com/packaging/2012/06/nuspec.xsd
http://schemas.microsoft.com/packaging/2013/01/nuspec.xsd
http://schemas.microsoft.com/packaging/2013/05/nuspec.xsd
http://www.w3.org
http://www.w3.org/2001/XMLSchema
https://api.github.com
https://github.com
microsoft.com
schemas.microsoft.com
www.w3.org
Info
Cryptographic algorithms detected in the binary:
Uses constants related to CRC32
Info
The PE is digitally signed.
Signer: Discord Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe
VirusTotal score: 0/70 (Scanned on 2026-06-23 10:36:13)
All the AVs think this file is safe.
MD5
749f0515f9a6aca9a83a5b73478e345b
SHA1
26983b5b890e1124cfb811699e3c7f7bd29aed78
SHA256
c91b844dad891bec0b857a38700b483bb64c79e9e955f335d1809eada2e3107d
SHA3
49747d15d0f303598f11ad83abce02bfbf8bd45841815731de993c50d1ca4951
SSDeep
12288:R6CyLEgR0ro/0EhcXAHjRYSN9bUlOr/oJfT9Pu0XejfQ1JRQ3Tzvx+nDIpnUR:aEgRN/th3VelBPu0XUfWJms0pnQ
Imports Hash
f34d5f2d4577ed6d9ceec516c1f5a744
e_magic
MZ
e_cblp
0x90
e_cp
0x3
e_crlc
0
e_cparhdr
0x4
e_minalloc
0
e_maxalloc
0xffff
e_ss
0
e_sp
0xb8
e_csum
0
e_ip
0
e_cs
0
e_ovno
0
e_oemid
0
e_oeminfo
0
e_lfanew
0x80
Signature
PE
Machine
IMAGE_FILE_MACHINE_I386
NumberofSections
3
TimeDateStamp
2021-Sep-20 20:18:53
PointerToSymbolTable
0
NumberOfSymbols
0
SizeOfOptionalHeader
0xe0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Magic
PE32
LinkerVersion
8.0
SizeOfCode
0x16ee00
SizeOfInitializedData
0x800
SizeOfUninitializedData
0
AddressOfEntryPoint
0x00170CBE (Section: .text)
BaseOfCode
0x2000
BaseOfData
0
ImageBase
0x400000
SectionAlignment
0x2000
FileAlignment
0x200
OperatingSystemVersion
4.0
ImageVersion
0.0
SubsystemVersion
4.0
Win32VersionValue
0
SizeOfImage
0x176000
SizeOfHeaders
0x200
Checksum
0x178379
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve
0x100000
SizeofStackCommit
0x1000
SizeofHeapReserve
0x100000
SizeofHeapCommit
0x1000
LoaderFlags
0
NumberOfRvaAndSizes
16
MD5
6f5e1a03b65e080d089709e5fc050469
SHA1
9f2950a386b35c14f9417ac26bedd40b7170c91d
SHA256
9abae4508a2e5060a19ff2206d12582301c504e3d26b9561c794ca446a2a11e4
SHA3
bc3c04e33698cf1c11747ab2010004e5ba713073df03a65206a92ef861c2507b
VirtualSize
0x16ecc4
VirtualAddress
0x2000
SizeOfRawData
0x16ee00
PointerToRawData
0x200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy
5.8438
MD5
a555553066ad1c5f40135d8388fea2a1
SHA1
8eb8bbfff6b32a1efba2c9d4d454f46667497870
SHA256
fb919699f852161f09016e754ac43e6c0940aebc5b8ef82c6667a768aab9526d
SHA3
6c5adf105b961f51c418745e4b0f98d876b6fa00a041fd4c5f16464383f3a0a3
VirtualSize
0x5c6
VirtualAddress
0x172000
SizeOfRawData
0x600
PointerToRawData
0x16f000
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy
4.15326
MD5
baf3a027a66e6ab07f3eca16ef1053e7
SHA1
859fb4ab425d739462bc7803ff29377382d70c39
SHA256
a4da81038fd353f31cc83d368ca71be34db65a9ce71bb1b82b33a3dab52f035a
SHA3
fe099a17cc17076ca0e70263096bca5e4d4900375f98ca7dc8a8f9d5873a9b75
VirtualSize
0xc
VirtualAddress
0x174000
SizeOfRawData
0x200
PointerToRawData
0x16f600
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy
0.0815394
Type
RT_VERSION
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x33c
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
3.32305
MD5
b003a8cad0e56c2cfd5427ff742bad3b
SHA1
27065115e9f17334ddc2edbb20b5489078364624
SHA256
30cb6b35300213570a01d636a497881639f2ed772b6a98b48af2727386b515e1
SHA3
356d68520f7b99fd52a1cb4d27b12562240a5ecebe62af45ea610efa28548127
Type
RT_MANIFEST
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x1ea
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
5.00112
MD5
b7db84991f23a680df8e95af8946f9c9
SHA1
cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256
539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3
4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff
Signature
0xfeef04bd
StructVersion
0x10000
FileVersion
1.1.1.0
ProductVersion
1.1.1.0
FileFlags
(EMPTY)
FileOs
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType
VFT_APP
Language
UNKNOWN
Comments
Update
CompanyName
GitHub
FileDescription
Update
FileVersion (#2)
1.1.1.0
InternalName
Update.exe
LegalCopyright
Copyright © GitHub 2013-2015
LegalTrademarks
OriginalFilename
Update.exe
ProductName
Update
ProductVersion (#2)
1.1.1.0
Assembly Version
1.1.1.0