Gridinsoft Logo

Presidio.dll Trojan Packed Analysis

Technical Analysis

File Name Presidio.dll
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.153.174
Database Version 2024-01-02 22:02:18 UTC

Trojan.Win64.Packed.ns

Malware family: Packed

Packed malware uses compression, encryption, or obfuscation techniques to alter code appearance and evade security detection. These methods modify the original malware structure to bypass signature-based detection systems and complicate analysis efforts.
N/A
Detection Rate
3,518,480
File Size (bytes)
2024-01-02
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
e52e1c0b3006e53821a6812b65776f55
SHA1
80e2254f1b5cc22e912991e4c45130c236c385e9
SHA256
22f17234d5b6c8e69ee612406d70b7a9c2cec1e96272cb912f0652b02344f629
SHA512
995c1a2a52ad928f9d4a79ed3bfca94fe6277cad8b4ddf78d5614f6f3703245395e885534aa7e1fde0e70b411afc3c9feda8b39f9939e4cd7b8e5bc23a499cc2
ImpHash
dab03522fe7618ebb94a66f43a593106

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1807c0058
Compilation Time 2023-12-19 22:24:21
Checksum 0x00361409 (Actual: 0x00361409)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 7 libraries
kernel32, USER32, WS2_32, dbghelp, ntdll, CRYPT32, ADVAPI32
Exports 0 functions
Resources 1 Resources
Sections 15 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00010000 927,160 bytes 412,160 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3ECB69BE24E49528B7C94E5F61B12163
0x00100000 811,488 bytes 272,384 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E1E7F29CB12106B0DAB313B7E2891AE9
0x001d0000 31,192 bytes 3,072 bytes 7.78 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 47BDDB221DFA209888D3E9A7D60B480F
0x001e0000 35,448 bytes 20,992 bytes 7.69 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6DBE17097E972AF1F6A78C271C5A0D1F
0x001f0000 8,720 bytes 1,536 bytes 7.46 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6610861C2505FC2EE4B388EBB88614E4
0x00200000 24 bytes 512 bytes 1.37 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 690009B99CDFE5D840298680902615B8
0x00210000 348 bytes 512 bytes 4.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C81C2310B452584438515970BA122DFC
0x00220000 488 bytes 512 bytes 6.13 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9185F99BCE1D9D9F54948FFF6E39F911
0x00230000 11,736 bytes 7,168 bytes 7.86 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 910F894E4CB3972AEF641DD615C9EFA6
.idata 0x00240000 65,536 bytes 512 bytes 3.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 80748CA0FA2662852D5BD587E22B2A0B
.tls 0x00250000 65,536 bytes 512 bytes 0.40 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E0AFCC596C7CB7B2FB2388486AB3D6AA
.rsrc 0x00260000 65,536 bytes 512 bytes 4.76 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0C2D91F71E35C2A027A5FBFDF6703AE8
.themida 0x00270000 5,529,600 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x007c0000 2,796,544 bytes 2,796,544 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ DFA3B48141A9BF43DCB44CBF855A30D0
.reloc 0x00a70000 65,536 bytes 16 bytes 2.53 (Normal) IMAGE_SCN_MEM_READ 175DE22EC855BA7E6CDC267D341F603B
Entropy Analysis Alert

6 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 1 (392 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 392 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.Packed.ns Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.Packed.ns without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware