Gridinsoft Logo

Test.exe Trojan Generic Analysis

Technical Analysis

File Name test.exe
File Type
PE32 executable (console) Intel 80386, for MS Windows
Scanner Version 1.0.172.174
Database Version 2024-04-19 11:00:26 UTC

Trojan.Win32.Generic.oa!s1

Malware family: Generic

This detection name identifies suspicious files displaying Trojan-like behavior patterns. It represents malware that masquerades as benign programs while executing unauthorized activities on the infected system.
N/A
Detection Rate
241,664
File Size (bytes)
2024-04-19
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b5207d7f8e3c64aa7a0824d2b5a1feab
SHA1
1dd138c58edead8691084aca08c9bcd586dbf941
SHA256
204b6e46050fc262b29fbc4f6b918458063becd7f6ac343b51d5212d282f2b18
SHA512
8a94dfed7d1db6c7394d6bfafd97b710cce97a0f92f3897701636e2460e9dc09d08dc0365291599fbf64d155697ea4c5c6b39cd9b9b3249a4eaba950b02ed1fb
ImpHash
0871daa0248acc51a46052dec3c43874

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x00431410
Compilation Time 2021-08-23 03:55:15
Checksum 0x00000000 (Actual: 0x00042b55)
OS Version 5.0
PEiD Signatures PE32 executable (console) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 8 libraries
oleaut32, advapi32, user32, kernel32, mpr, MSVCRT, msvcrt, shell32
Exports 0 functions
Resources 17 Resources
Sections 10 Sections

Version Information

CompanyName
FileDescription
FileVersion 0. 0. 0. 0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
ProductVersion 0.0.0.0
Comments
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 193,400 bytes 193,536 bytes 6.34 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 8337DE219A4AA013625ED2C3628D7699
.itext 0x00031000 2,268 bytes 2,560 bytes 5.54 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ F955F7984C6DF91C85AEF36F674A05B5
.data 0x00032000 7,784 bytes 8,192 bytes 3.88 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CA30614605380FB19D517A8373BD36AD
.bss 0x00034000 101,596 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x0004d000 5,732 bytes 6,144 bytes 4.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 657266889EA49925284FDD1A44846194
.didata 0x0004f000 304 bytes 512 bytes 2.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE EE535B6EB9CA18C4F524AC168750751C
.tls 0x00050000 8 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00051000 24 bytes 512 bytes 0.17 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4689F7ACCD8935C419D3CFEEC99737E2
.reloc 0x00052000 14,744 bytes 14,848 bytes 6.63 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 50C50CB2C359FB8E816EB48A82085E03
.rsrc 0x00056000 14,276 bytes 14,336 bytes 3.62 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1160AC7FFF33B1E5ECD43A4EDE3CFD5A
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 17 (13,310 bytes)
Resource Type Count Total Size Percentage
RT_STRING 12 12,572 bytes
94.5%
RT_RCDATA 4 102 bytes
0.8%
RT_VERSION 1 636 bytes
4.8%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Generic.oa!s1 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Generic.oa!s1 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware