Gridinsoft Logo

Uploaded_file Trojan Gen Analysis

Technical Analysis

File Name uploaded_file
Scanner Version 1.0.136.174
Database Version 2023-09-08 22:06:23 UTC

Trojan.Win32.Gen.ns

Malware family: Gen

This is a generic detection identifier for files exhibiting Trojan horse characteristics. It indicates malware that disguises itself as legitimate software while containing malicious code designed to compromise system security or steal information.
N/A
Detection Rate
11,277,312
File Size (bytes)
2023-09-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
99be619acbefc3374140a8acbd32b40c
SHA1
23b5ed679032b42241a751ac51d49d8f3a85fb00
SHA256
47d492d44ff9fb66ad87d05b6b697b6ea531100023c920a95c379d6623f95ff6
SHA512
e0ced0c29dbfbff63fafa3787bb06a3439d229a79ee164fc9ca274a0f4f373dfff23e49d95387112d0bc8650f004fbc5a9a1ee06fde88ee2765b9cbbb33a8e39
ImpHash
f8b22793fe268a874555864bcf89f274

PE Analysis

Basic Information

Image Base 0x00e00000
Entry Point 0x00e036f1
Compilation Time 2016-10-11 14:04:50
Checksum 0x00000000 (Actual: 0x00ac5521)
OS Version 6.0
PEiD Signatures No signatures detected
PDB Path C:\Users\Admin\documents\visual studio 2015\Projects\AntiDetectCrack\Release\AntiDetectCrack.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 5 libraries
kernel32, msvcp140, user32, vcruntime140, ucrtbase
Exports 0 functions
Resources 9 Resources
Sections 10 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 16,384 bytes 12,800 bytes 6.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2F81E8A4239034A675BB0BC9FE76D68C
0x00005000 8,192 bytes 4,096 bytes 4.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 04DB2DECC497CB74BDCB76D945760A1D
0x00007000 4,096 bytes 1,024 bytes 2.96 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 49A205FF43816331D13678FC3B3C07EC
0x00008000 4,096 bytes 512 bytes 0.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F667BFE69B402A9F5DBBF49CAB2EE30C
0x00009000 6,082,560 bytes 5,709,312 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FDAF07C810488FEA17196580174A08D8
0x005d6000 4,096 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x005d7000 372,736 bytes 371,200 bytes 6.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 39C32EA4C60BCA7B1F1E95AAE8FA703A
0x00632000 3,543,040 bytes 3,539,968 bytes 3.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 67C0F50C9F69659E13BA783F496B7E77
.data 0x00993000 733,184 bytes 729,600 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FDE014E8DADD2106ECD0EE0CC0A70E66
.idata 0x00a46000 925,696 bytes 907,776 bytes 5.23 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8219D3269B185E8BCFEDC1FC321B130B
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 9 (6,792,391 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 1,083,120 bytes
15.9%
RT_RCDATA 1 5,708,800 bytes
84%
RT_GROUP_ICON 1 90 bytes
0%
RT_MANIFEST 1 381 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Gen.ns Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Gen.ns without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware