Gridinsoft Logo

EasyAntiCheat_EO.exe Trojan Sabsik Analysis

Technical Analysis

File Name EasyAntiCheat_EO.exe
File Type
PE32 executable (console) Intel 80386, for MS Windows
Scanner Version 1.0.150.174
Database Version 2023-11-29 08:01:03 UTC

Ransom.Win32.Sabsik.sa

Malware family: Sabsik

Sabsik is a malware variant capable of downloading additional payloads, including ransomware components. It can encrypt user files and initiate ransom demands. This threat represents a multi-stage attack where initial infection leads to more severe system compromise.
N/A
Detection Rate
1,514,272
File Size (bytes)
2023-11-29
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
cc43aa06e8809eac850312c49a20afd6
SHA1
2f5766333a259e81c421e5b288c678ed19d34af7
SHA256
04a076e5c404ecbae1fefcf33d61caa185c6dffcbba53966678e91e550937712
SHA512
62217db74d33c954a070024e03297f38a8a6cb92e23f06692af17ddca1bc58426aca548c3822449098dbd2e1baeceb6b3a62d80867e292d9ab144ea205181e53
ImpHash
9207da9a0ce5c03fd6793615b1132500

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004011d1
Compilation Time 2023-11-28 11:25:57
Checksum 0x00000000 (Actual: 0x00180eb2)
OS Version 6.0
PEiD Signatures PE32 executable (console) Intel 80386, for MS Windows
PDB Path C:\g0pl36kext3\Internal.pdb
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 2 libraries
GDI32, KERNEL32
Exports 1 functions
Resources 0 Resources
Sections 8 Sections

Digital Signatures

DigiCert Assured ID Root CA DigiCert Inc (US)
Thawte Timestamping CA Symantec Corporation (US)
Symantec Time Stamping Services CA - G2 Symantec Corporation (US)
DigiCert SHA2 Assured ID Code Signing CA Valve (US)
DigiCert Assured ID Root CA DigiCert Inc (US)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 742,749 bytes 742,912 bytes 5.81 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 84748E63FC398B0FC2EE7B0DFD29CFB4
.rdata 0x000b7000 107,987 bytes 108,032 bytes 4.11 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 69E100579243AFF205FBFBFF4FCF12DB
.data 0x000d2000 16,784 bytes 9,216 bytes 3.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3639BB1A264E2661564D230FE046F887
.idata 0x000d7000 4,763 bytes 5,120 bytes 4.69 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 546E99D35952315D80AA585416F59A85
.BSs 0x000d9000 614,660 bytes 614,912 bytes 6.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A428CCE1DA8BCA913BC36433D18DF0AE
.tls 0x00170000 777 bytes 1,024 bytes 0.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C573BD7CEA296A9C5D230CA6B5AEE1A6
.00cfg 0x00171000 270 bytes 512 bytes 0.11 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ ACC869C89B9D07DEB4EB75665EA5E0B4
.reloc 0x00172000 24,171 bytes 24,576 bytes 5.88 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ EC74B6467DB30FDDC0D16345ABF88446

Certificate Chain Analysis

Certificate #1
Subject DigiCert Assured ID Root CA
DigiCert Inc
US
Issuer DigiCert Assured ID Root CA
Serial Number 17154717934120587862167794914071425081
Certificate #2
Subject Symantec Time Stamping Services CA - G2
Symantec Corporation
US
Issuer Thawte Timestamping CA
Serial Number 168250781398245547403531165097821404219
Certificate #3
Subject Symantec Time Stamping Services Signer - G4
Symantec Corporation
US
Issuer Symantec Time Stamping Services CA - G2
Serial Number 19688950797630895426199952712430983760
Certificate #4
Subject Valve
Valve
US
Issuer DigiCert SHA2 Assured ID Code Signing CA
Serial Number 11031994125476529557404351784660246833
Certificate #5
Subject DigiCert SHA2 Assured ID Code Signing CA
DigiCert Inc
US
Issuer DigiCert Assured ID Root CA
Serial Number 5364131601516814570659357524942475272
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Ransom.Win32.Sabsik.sa Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win32.Sabsik.sa without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware