File Name | BaldrSky.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-14 09:00:23 UTC |
Malware family: Heuristic
Hash Type | Value | Action |
---|---|---|
MD5 |
a40d0460e1b79ff2c928c7618970fd9a
|
|
SHA1 |
e9a637321d0067877ec0d177319fb26abba323a7
|
|
SHA256 |
2843bc660722205fb5aaedf41b73a3243f1c0880b90eba576e7b9ad54c06c437
|
|
SHA512 |
c21b4f27345654cfab0230d8b6012895c78007b0c4f8748ef2ceaafb920a63b1315118e7470b803111fc6688841d8ededd94f60bf8a8bca2376f9d5e7e400c52
|
|
ImpHash |
9f01f86046281d58991ff9157228e31c
|
Icon |
Hash: 91ddffa60b78f843d68b90069d2ddb38
Fuzzy: e07402e2488f0d1c5e840c39aed1e2ea dHash: f0e0ece6749ce470 |
Image Base | 0x00400000 |
Entry Point | 0x00643914 |
Compilation Time | 2010-02-26 01:44:40 |
Checksum | 0x003b1184 (Actual: 0x003b5f9f) |
OS Version | 5.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | The expected hash does not match the digest in SpcInfo |
Imports | 13 libraries |
Exports | 0 functions |
Resources | 41 Resources |
Sections | 6 Sections |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
3,150,579 bytes | 3,150,848 bytes | 6.54 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
A6B6F5E68DE7527500B42AA967CCD926 |
.rdata |
0x00303000 |
401,002 bytes | 401,408 bytes | 5.34 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
7289C17BD556BFE2EAB0D955B517BF7B |
.data |
0x00365000 |
4,538,024 bytes | 98,304 bytes | 5.71 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
302BAC1450B87224BA53E4B1C5AD6C78 |
.rsrc |
0x007b9000 |
29,328 bytes | 29,696 bytes | 4.07 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B2E652ECBC56EF02EDFCC9006F4C056A |
.patch |
0x007c1000 |
12,288 bytes | 8,863 bytes | 5.56 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
70F8152035C62CE77CC9A10F46B1780E |
.bind |
0x007c4000 |
141,456 bytes | 141,456 bytes | 7.96 (Packed/Encrypted) |
IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
DF98E8C763B747F4E1BB4BE202851CD3 |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 1 | 4,264 bytes | |
RT_MENU | 1 | 132 bytes | |
RT_DIALOG | 38 | 22,748 bytes | |
RT_GROUP_ICON | 1 | 20 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
The expected hash does not match the digest in SpcInfo
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Trojan.Heur!.01012031 without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system