RouterScan.exe threat report

MD5 11d55e9ac224e91ac6c9db4d108983ff
Latest seen 2025-11-07 23:00:56 (6 months ago)
First seen 2025-08-23 23:00:42 (9 months ago)
Size 2 MB
Publisher Stas'M Corp.

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Gen. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Gen
Recommended action
Scan and remove
Last analysis
2025-11-07 23:00:56 (6 months ago)
File hash
11d55e9ac224e91ac6c9db4d108983ff
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Gen.

Timeline

First seen 2025-08-23 23:00:42 (9 months ago); latest analysis 2025-11-07 23:00:56 (6 months ago).

Publisher context

Company metadata: Stas'M Corp.. Product metadata: Router Scan by Stas'M.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

RouterScan.exe is a Windows file recorded in the ThreatInfo database. It is associated with Router Scan by Stas'M. The reported company name is Stas'M Corp.. The current detection status is Trojan.Gen, based on the latest analysis from 2025-11-07 23:00:56 (6 months ago).

If RouterScan.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Gen.

Product Name: Router Scan by Stas'M
Company Name: Stas'M Corp.
MD5: 11d55e9ac224e91ac6c9db4d108983ff
Size: 2 MB
First Published: 2025-08-23 23:00:42 (9 months ago)
Latest Published: 2025-11-07 23:00:56 (6 months ago)
Status: Trojan.Gen (on last analysis)
Analysis Date: 2025-11-07 23:00:56 (6 months ago)
RouterScan.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%mydoc%\b0ts
%profile%\downloads\router scan 2.53 portable by stasm (1).zip

ThreatInfo has observed RouterScan.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

50.0%
50.0%

The strongest geographic signal for this file is Egypt with 50.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for RouterScan.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

RouterScan.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x00213d38

PE Sections:

Name Size of data MD5
.text 2163200 53e70eea199acbcdee13a1b83afb951b
.itext 7680 9df73d567b9940af77bcc9d46e33931a
.data 60416 f9d08e4b3f824b05dd19abebca9341f2
.bss 0 d41d8cd98f00b204e9800998ecf8427e
.idata 15872 630b8f21f5a1be7835de16e8aa99f677
.didata 1024 40022238d9b62f2f448f917196a82af9
.tls 0 d41d8cd98f00b204e9800998ecf8427e
.rdata 512 1830ef0d68ea851c86d11deb68a499e2
.reloc 180736 dd928ab5604fe9caa24d7428f4eb5dd7
.rsrc 331264 987e2a572b8176e64c2cf94551773f56

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: