bCleanup.exe file report

MD5 ebd37b1276b3fe5b970fb8c276dbb3ca
Latest seen 2021-12-16 21:13:29 (4 years ago)
First seen 2021-12-16 21:13:29 (4 years ago)
Size 9 MB
Publisher Softland
Product Backup4all
Signed by Softland SRL

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for bCleanup.exe. ThreatInfo does not have a final classification for this sample yet.

bCleanup.exe is a Windows file recorded in the ThreatInfo database. It is associated with Backup4all. The reported company name is Softland. The current detection status is Undefined, based on the latest analysis from 2021-12-16 21:13:29 (4 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: Backup4all
Company Name: Softland
MD5: ebd37b1276b3fe5b970fb8c276dbb3ca
Size: 9 MB
First Published: 2021-12-16 21:13:29 (4 years ago)
Latest Published: 2021-12-16 21:13:29 (4 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2021-12-16 21:13:29 (4 years ago)
Signed By: Softland SRL
Status: Valid

The signature on bCleanup.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%\softland

ThreatInfo has observed bCleanup.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Russian Federation with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for bCleanup.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

bCleanup.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0185d058

PE Sections:

Name Size of data MD5
3818496 2d3eff6e53582cbdd32b0a328ab78ca9
15360 a934e475e743215021f9403a044a5e1f
268800 8979eadfad792b593b1f77f00f83601e
.bss 0 d41d8cd98f00b204e9800998ecf8427e
3072 5979d99292d52d31504abb2aa2d7de76
1536 0921763387159eaa11b9ad7774a9f10a
512 950ab0a4596d89cffa48e35e14359fc3
.tls 0 d41d8cd98f00b204e9800998ecf8427e
512 bc5f1f796fbda5c1aa5a338cf2c3af26
420864 b8a6b003e980ccd854166f388ca362cc
203776 23e6b9a099a68da4bcabc373ec3f15f9
.edata 512 8e3b586c8981ef944a2b1d5180931b27
.idata 2048 3f2cdf95373389df53f176028ab9b1d7
.tls 2048 368fc55c7e4176e1783f6d17cac75c90
.rsrc 50688 160ba81c58acec98a2b0eda04655f103
.themida 0 d41d8cd98f00b204e9800998ecf8427e
.boot 5054976 76a4219cf26b8b35c16ab48d06a7de5c
.reloc 16 f5582b711a252df3d17e83a513df93ae

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: