GridinSoft Threat Intelligence

f671501952.exe threat report

Detected as Trojan.Generic File reputation report
MD5 0424aba641fe4cb8f58f60ccc1e6914b
Latest seen 2026-05-25 12:00:56 (2 days ago)
First seen 2026-05-16 06:00:20 (2 weeks ago)
Size 10 MB

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Generic. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Generic
Recommended action
Scan and remove
Last analysis
2026-05-25 12:00:56 (2 days ago)
File hash
0424aba641fe4cb8f58f60ccc1e6914b
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Generic, part of the Trojan threat category.

Category context

Malware disguised as legitimate software or delivered through deceptive packaging. Related Trojan reports help compare this file with nearby detections, publishers, and hashes.

Timeline

First seen 2026-05-16 06:00:20 (2 weeks ago); latest analysis 2026-05-25 12:00:56 (2 days ago).

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present. Review the Trojan category for related samples and common context.

f671501952.exe is a Windows file recorded in the ThreatInfo database. The current detection status is Trojan.Generic, based on the latest analysis from 2026-05-25 12:00:56 (2 days ago). ThreatInfo groups this verdict with Trojan reports for broader family-level investigation.

If f671501952.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Generic.

MD5: 0424aba641fe4cb8f58f60ccc1e6914b
Size: 10 MB
First Published: 2026-05-16 06:00:20 (2 weeks ago)
Latest Published: 2026-05-25 12:00:56 (2 days ago)
Status: Trojan.Generic (on last analysis)
Analysis Date: 2026-05-25 12:00:56 (2 days ago)
f671501952.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%desktop%\new folder (5)

ThreatInfo has observed f671501952.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for f671501952.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

f671501952.exe is identified as pe for 64-bit systems. The subsystem is Native. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Native
Entry point 0x00992010
Image base 0x0000000140000000

PE Sections:

Sections 33
Raw data 10857472

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.rdata 817664 bytes · 7.5% of section data
MD5 8ba7f8664c3fb5093cb36862a152a481
.pdata 424960 bytes · 3.9% of section data
MD5 1f9dd4f5486249bd64a61d9d736c22d6
.idata 8704 bytes · 0.1% of section data
MD5 75b53d027d3d95c84b2a5075920013af
.edata 101888 bytes · 0.9% of section data
MD5 0cc661d3d34d4a26c2e17efb2334606e
PROTDATA 512 bytes · 0.0% of section data
Uncommon name
MD5 bf619eac0cdf3f68d496ea9344137e8b
GFIDS 36352 bytes · 0.3% of section data
Uncommon name
MD5 322c63a7a1768aa49dc390b3fb3562ec
Pad1 0 bytes · 0.0% of section data
Uncommon name
MD5 d41d8cd98f00b204e9800998ecf8427e
.text 3984896 bytes · 36.7% of section data
MD5 2c4c3bddb3af5be9160ca3a0a7797a52
PAGE 3950592 bytes · 36.4% of section data
Uncommon name
MD5 002cfcc3f06bbc6bb5430175c102f7e8
PAGELK 151552 bytes · 1.4% of section data
Uncommon name
MD5 cc729d7aedbc5061c7c17d30c29b69f5
POOLCODE 1536 bytes · 0.0% of section data
Uncommon name
MD5 f28630ddfc4216d2162455ce08295663
PAGEKD 23552 bytes · 0.2% of section data
Uncommon name
MD5 b950ebdfa86f6c41faf8cecc5038c70e
PAGEVRFY 205312 bytes · 1.9% of section data
Uncommon name
MD5 f916f88ba16b1285b97dde7f179c2663
PAGEHDLS 9728 bytes · 0.1% of section data
Uncommon name
MD5 86187e2d100526a00f60deac1a144e2a
PAGEBGFX 27136 bytes · 0.2% of section data
Uncommon name
MD5 f6af073fe40f4ee08f8861be9a817731
INITKDBG 103936 bytes · 1.0% of section data
Uncommon name
MD5 c7db193aaa5f2cddb0ab977f8d185f94
TRACESUP 6144 bytes · 0.1% of section data
Uncommon name
MD5 b38fe3c517e527ea4a8eddfe225b21ef
KVASCODE 9728 bytes · 0.1% of section data
Uncommon name
MD5 51fabeebd85d0957bf2313d25413fe85
RETPOL 2048 bytes · 0.0% of section data
Uncommon name
MD5 7a21fb14d2abc74066b126b309e49587
MINIEX 9728 bytes · 0.1% of section data
Uncommon name
MD5 7751b8377bbe96db917aba74887140ad
INIT 567296 bytes · 5.2% of section data
Uncommon name
MD5 4fabe7fe523d599e8129b2f0e1100423
Pad2 0 bytes · 0.0% of section data
Uncommon name
MD5 d41d8cd98f00b204e9800998ecf8427e
.data 77824 bytes · 0.7% of section data
MD5 e75103f04b63877db8af437a087041d7
ALMOSTRO 5120 bytes · 0.0% of section data
Uncommon name
MD5 f9b5543e5dbc1869dac865acdef49e26
CACHEALI 512 bytes · 0.0% of section data
Uncommon name
MD5 87bd0d8874d15a38f67f869e1dbeb9cb
PAGEDATA 6144 bytes · 0.1% of section data
Uncommon name
MD5 264083619caa27dbd1a6c421c23b752a
PAGEVRFD 32768 bytes · 0.3% of section data
Uncommon name
MD5 1c03e059551d01a84f053698d847a116
INITDATA 2048 bytes · 0.0% of section data
Uncommon name
MD5 1c8953099626a9ca08626e212156bf67
Pad3 0 bytes · 0.0% of section data
Uncommon name
MD5 d41d8cd98f00b204e9800998ecf8427e
CFGRO 7680 bytes · 0.1% of section data
Uncommon name
MD5 4ccfc6a81d05a68a3bccb7fc5890d2c8
Pad4 0 bytes · 0.0% of section data
Uncommon name
MD5 d41d8cd98f00b204e9800998ecf8427e
.rsrc 242176 bytes · 2.2% of section data
MD5 d80d99fbc1902fdb9e6995de37c343fb
.reloc 39936 bytes · 0.4% of section data
MD5 50407c51b49b88ba65c3a90bd23bf70c

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Trojan.Generic

This report identifies f671501952.exe by MD5 0424aba641fe4cb8f58f60ccc1e6914b. It is part of the Trojan report group. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with 0424aba641fe4cb8f58f60ccc1e6914b.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found. Use the Trojan category to compare similar reports.