Gridinsoft Logo

The SickoLoader.exe File Analysis

Technical Analysis

File Name SickoLoader.exe
File Type
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Scanner Version 1.0.219.174
Database Version 2025-06-24 08:00:15 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
143,360
File Size (bytes)
2025-06-24
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
fb25c3bbaeba2a1d985f7758f217985b
SHA1
4ee7012a41c58943fba5e62a2721581d1ed5f8c8
SHA256
0df951598cf8649a271c3e668b021b229d202a7b3753b4d4f4a8e9608e259196
SHA512
16da8d44f02f672e0b12582da1a6525786abd6d7e4acbba969f5dbdf9788dc03665c8eedb55eca7e080b634d7a7f1506c1a75f195762944dae3336e3e6140e64
ImpHash
e1f98e42df5bf941344cfece007ef84c

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004014f0
Compilation Time 2025-05-30 19:02:56
Checksum 0x00031a24 (Actual: 0x00031a24)
OS Version 4.0
PEiD Signatures PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
gdiplus, KERNEL32, msvcrt
Exports 0 functions
Resources 0 Resources
Sections 9 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 115,744 bytes 116,224 bytes 6.17 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_16BYTES 43B1AA131894AEEAF2A3084546BB09FC
.data 0x0001e000 400 bytes 512 bytes 1.14 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES 8D53CB8ADE556B8BAA84A780BBA2FAA3
.rdata 0x0001f000 13,760 bytes 13,824 bytes 5.03 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES D9E3BD4EA95FDABAB2BB61ADA5C735F8
.pdata 0x00023000 3,468 bytes 3,584 bytes 5.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 9EE147B38FE4851F6ECAC22C8384AD6B
.xdata 0x00024000 3,376 bytes 3,584 bytes 4.25 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES E6D88AFB1812ABB165FCC564F13133E5
.bss 0x00025000 5,696 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES D41D8CD98F00B204E9800998ECF8427E
.idata 0x00027000 3,488 bytes 3,584 bytes 4.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES 6C3DBDDBB191775E3919AABBFCCFACC5
.CRT 0x00028000 104 bytes 512 bytes 0.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_8BYTES 5AA50D5AB43DAF0806CE51CDFBC7B000
.tls 0x00029000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_8BYTES BF619EAC0CDF3F68D496EA9344137E8B

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware