deadspace2.exe threat report

MD5 63879a97036c8383071ce25b2f184022
Latest seen 2024-07-25 23:01:23 (2 years ago)
First seen 2019-08-06 16:22:46 (6 years ago)
Size 60 MB
Product Dead Space™ 2

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for deadspace2.exe. ThreatInfo currently classifies this sample as Trojan.Heur!.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows deadspace2.exe detected as Trojan.Heur!. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
Trojan.Heur!
Last analysis
2024-07-25 23:01:23 (2 years ago)
File hash
63879a97036c8383071ce25b2f184022
Download Anti-Malware

deadspace2.exe is a Windows file recorded in the ThreatInfo database. It is associated with Dead Space™ 2. The reported company name is Electronic Arts Inc.. The current detection status is Trojan.Heur!, based on the latest analysis from 2024-07-25 23:01:23 (2 years ago).

If deadspace2.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: Dead Space™ 2
Company Name: Electronic Arts Inc.
MD5: 63879a97036c8383071ce25b2f184022
Size: 60 MB
First Published: 2019-08-06 16:22:46 (6 years ago)
Latest Published: 2024-07-25 23:01:23 (2 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2024-07-25 23:01:23 (2 years ago)
deadspace2.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\محتویات فلش\tools\crack
%sysdrive%\محتویات فلش\tools\crack
%sysdrive%\hry
%sysdrive%\hry
%programfiles%
%programfiles%
%sysdrive%\games

ThreatInfo has observed deadspace2.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

28.6%
28.6%
28.6%
14.3%

The strongest geographic signal for this file is Iran, Islamic Republic of with 28.6% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 71.4%
Windows 7 28.6%

The most common operating system signal for deadspace2.exe is Windows 10 with 71.4% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

deadspace2.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x010314be

PE Sections:

Name Size of data MD5
.text 23719936 2ff4bd58b22ae7bd67535833bbbb1e95
.rdata 1630720 a1dd1f98086c8fdb96bef3f59c037de2
.data 3461632 4dfe0e164e017b19efbff00b5bfa201c
.idata 10240 f5a70b5f43f9dd9cfc292377616c6119
.tls 512 e0a9ee87f03d0a7a86de67592365f7d9
.rsrc 17408 23a47542ff21c0fb53213fd3f9caa010
.reloc 2247168 e1b23acb3b84442d704b716be5d4e438
S1 4096 080ac52440070f6bc357466bca609717
S2 67072 d3b6b8af4e846f26fbf60d7d4457f2bd
S3 15881728 5099a5ff93556b4fa897347dff4304e5
S4 16159744 4f6ddfb97d05b0969f87257d19dc5d0b

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: