Gridinsoft Logo

Ipspeedtest-windows-amd64.exe Trojan Sabsik Analysis

Technical Analysis

File Name ipspeedtest-windows-amd64.exe
File Type
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Scanner Version 1.0.174.174
Database Version 2024-05-03 06:00:25 UTC

Ransom.Win64.Sabsik.cld

Malware family: Sabsik

Sabsik is a malware variant capable of downloading additional payloads, including ransomware components. It can encrypt user files and initiate ransom demands. This threat represents a multi-stage attack where initial infection leads to more severe system compromise.
N/A
Detection Rate
5,223,424
File Size (bytes)
2024-05-03
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
19ecee7c33a8799bdba9bffc8e729490
SHA1
d91d29a75afb9f88779a1b1da0a8ea098c45cac9
SHA256
3362168076440af6f6e9ccbe3fed4d2d346eb02d8bf2fd55906ed81bbd8f08eb
SHA512
ad3218b133555cb29ab2db0bb97276ee3243d817fa9295cbd374439073b15e0dab902a2ed40ecf42b223ed04099462fee27fb787f99212ba5f71f27524a6a567
ImpHash
f0ea7b7844bbc5bfa9bb32efdcea957c

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004669e0
Compilation Time 1970-01-01 00:00:00
Checksum 0x00000000 (Actual: 0x00509b5c)
OS Version 6.1
PEiD Signatures PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 1 libraries
kernel32
Exports 0 functions
Resources 0 Resources
Sections 6 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,542,458 bytes 2,542,592 bytes 6.17 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ AA3859F836F88A4B5242B2885491F7DC
.rdata 0x0026e000 2,390,520 bytes 2,390,528 bytes 5.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FE86574A7A1DED359E638873787398D9
.data 0x004b6000 626,576 bytes 244,736 bytes 5.33 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2CCE455CBE365345F62D4F1E5859833F
.idata 0x0054f000 1,168 bytes 1,536 bytes 3.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 42400EDC6751B080563D3CB7855B24D3
.reloc 0x00550000 41,842 bytes 41,984 bytes 5.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 617C6C33F0799004AE253849D3C67E5E
.symtab 0x0055b000 4 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 07B5472D347D42780469FB2654B7FC54

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Ransom.Win64.Sabsik.cld Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win64.Sabsik.cld without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware