Gridinsoft Logo
File Icon

MACRO R6.exe Trojan Gen Analysis

Technical Analysis

File Name MACRO R6.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-27 00:01:13 UTC

Trojan.Win32.Gen.cl

Malware family: Gen

This is a generic detection identifier for files exhibiting Trojan horse characteristics. It indicates malware that disguises itself as legitimate software while containing malicious code designed to compromise system security or steal information.
N/A
Detection Rate
1,907,200
File Size (bytes)
2025-03-27
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c0e5b07cbf2d02c54f39ce6aad676dc7
SHA1
4100b839d867b252ffa991f91fb9e403b8e41256
SHA256
0198b7c285a13c98123bbcf85d1b072bcc00f225f6d30867f4ab3be1ea927da8
SHA512
7e87ca707772bcfd2121f350a001c36a5eda420e39f4612ef2d36f0b00734837bf5435421a1f005bf88ce4c6f83c79f10c46e8f7d9a793b9f970f88b8a64d87f
ImpHash
d9d89a540ccdbb6ae8951f49668ccb3f

PE Analysis

Basic Information

Icon
Hash: e0cb087695e0e7a87d612029549ba9cf
Fuzzy: 2f26a13d710fb4ee3dc0c8ddd37f2645
dHash: 00334d4d2b8e4d2a
Image Base 0x00400000
Entry Point 0x004f0ee8
Compilation Time 2019-08-29 16:15:30
Checksum 0x00000000 (Actual: 0x001e053d)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 11 libraries
Exports 0 functions
Resources 60 Resources
Sections 10 Sections

Version Information

CompanyName Valve Corporation
FileDescription Steam Client Bootstrapper
FileVersion 1.0.0.1
InternalName steamcmd
LegalCopyright Copyright (C) 2010 Valve Corporation
LegalTrademarks
OriginalFilename steam.exe
ProductName Steam Client Bootstrapper
ProductVersion 1.0.0.0
Comments
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 975,440 bytes 975,872 bytes 6.51 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 0B0D3477F81FBCDB7E351BEC5DC7FD60
.itext 0x000f0000 3,928 bytes 4,096 bytes 6.05 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BE92FDBC8C2D4BFCD659356617210538
.data 0x000f1000 26,732 bytes 27,136 bytes 6.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 42BEF51D694018618D6678AFC246F70B
.bss 0x000f8000 22,268 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x000fe000 12,996 bytes 13,312 bytes 5.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C679857E9BCBCC793029EF4CA1DA82D1
.didata 0x00102000 806 bytes 1,024 bytes 3.33 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0B33D2418C11C274EEBEBAD860A8CFB3
.tls 0x00103000 60 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00104000 24 bytes 512 bytes 0.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D6A2B773BED77F9E3FF2515AF9F9BF99
.reloc 0x00105000 77,740 bytes 77,824 bytes 6.70 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8F7C6F01E0E5201476F7AC71386FE713
.rsrc 0x00118000 806,400 bytes 806,400 bytes 2.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 20FA1EE8EF5A8761A92E1B8C8260715B
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 60 (802,852 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 7 2,156 bytes
0.3%
RT_BITMAP 12 4,964 bytes
0.6%
RT_ICON 6 369,968 bytes
46.1%
RT_STRING 21 17,828 bytes
2.2%
RT_RCDATA 4 406,123 bytes
50.6%
RT_GROUP_CURSOR 7 140 bytes
0%
RT_GROUP_ICON 1 90 bytes
0%
RT_VERSION 1 860 bytes
0.1%
RT_MANIFEST 1 723 bytes
0.1%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Gen.cl Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Gen.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware