f57714656.exe threat report

MD5 bf7226bdcfcfc5f56bc658625e90418d
Latest seen 2023-04-01 23:13:15 (3 years ago)
First seen 2023-04-01 23:13:15 (3 years ago)
Size 6 MB
Publisher Intel Corporation

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2023-04-01 23:13:15 (3 years ago)
File hash
bf7226bdcfcfc5f56bc658625e90418d
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic.

Timeline

First seen 2023-04-01 23:13:15 (3 years ago); latest analysis 2023-04-01 23:13:15 (3 years ago).

Publisher context

Company metadata: Intel Corporation. Product metadata: Intel® Wireless WiFi Link Adapter.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

f57714656.exe is a Windows file recorded in the ThreatInfo database. It is associated with Intel® Wireless WiFi Link Adapter. The reported company name is Intel Corporation. The current detection status is Trojan.Generic, based on the latest analysis from 2023-04-01 23:13:15 (3 years ago).

If f57714656.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

Product Name: Intel® Wireless WiFi Link Adapter
Company Name: Intel Corporation
MD5: bf7226bdcfcfc5f56bc658625e90418d
Size: 6 MB
First Published: 2023-04-01 23:13:15 (3 years ago)
Latest Published: 2023-04-01 23:13:15 (3 years ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2023-04-01 23:13:15 (3 years ago)
f57714656.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%desktop%\recuperados

ThreatInfo has observed f57714656.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Mexico with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for f57714656.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

f57714656.exe is identified as pe for 64 systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Native
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000255f8

PE Sections:

Name Size of data MD5
.text 3265536 c90b7061e4a3a8f6bfb1fa24bdbb9db1
.rdata 662016 bc6d617141f3f413cca2812d28ba46bd
.data 126464 d396670975f60f976039ed0b97c7415b
.pdata 187904 d0bfc1642c8455a610ce5e4d5e11f80e
.gfids 512 877dce5975b4adc844166285b3d5393a
PAGEcsrv 89088 282d4a09ed841079ff63466cbe04e7a0
PAGEcjaw 86528 158f40b86d50980722b6af93f0e6d651
PAGEcwfd 64512 2b8d87835c6fdecbea64d2cbe7bb2974
PAGE 1536 031612ac294433cbd1f89490a79e2095
PAGEcnlo 1024 2c033b0267a89ea30cbe21e8b2a7ec65
PAGEccln 52736 580533c080bd8a02a0ff385ad3991c94
PAGEcsec 30720 4c3088eae288d1ab415e0e098f615d52
PAGEcsv_ 57856 fd0d4b69ca961fdf18f968baef6f7314
PAGEcimg 5632 94564c5f9aa1855ad5b003d40efc7a84
PAGEcast 10752 939b7f5fd730daf77f4394397b207da9
PAGEcpsm 7168 66f3cd1643414dd2474dba1ef64a37ea
PAGEcctw 2560 eaac011bcd51c03d7962b6f1f946b4c5
PAGEdoid 29184 32f87d0cc64392549f8faa98e3ae9a16
PAGEdcln 4096 557a6e31349d84409f54954d3735a80b
PAGEdsv_ 2560 f160403194d5fabee31246df7fa27088
PAGEdreg 256512 3c4294b85b8bb29aaa730dca3596cdfe
PAGEdscn 512 8672a4d2ffffe8b8c4936f2ef2b283f0
PAGEdwi2 2560 cb4f26a478da758bc0a27c4037f63433
PAGEdStn 2560 b563d993fea6751a283207f87561eccf
PAGEdSnd 2560 cdcd21cbb02ef17da2d4713718fb97e8
PAGEdSnF 2560 816a6129b22560ea1e2a126b82256886
PAGEdPsr 2048 2809805677b07c5a53c113206bde3824
PAGEdwi1 2560 64cba1fa7c6114ad533c3062f5a40825
PAGEdjaw 1536 01827a9fdb239506259b4600ad966e76
PAGEdctw 512 f794dcd5b00d814d12cac3ee63e5039c
PAGEdimg 1536 1a60e2f7b0720e8752330da50fb01ec6
PAGEdrlg 2097152 b2d1236c286a3c0704224fe4105eca49
INIT 4608 0bf02124fac867834f7f2dde55ca7671
.rsrc 27648 40dcdcabe61c5cdc69aeb8472e2bc8e2
.reloc 20992 b2416fb76d4e04387c44dce45f2a2639

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: