Setup exe Trojan Wacatac File Malware Analysis: eaca902c39d57b5db11495414536e183
Gridinsoft Logo
File Icon

Setup.exe Trojan Wacatac Analysis

Technical Analysis

File Name Setup.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.153.174
Database Version 2023-12-31 19:01:40 UTC

Ransom.Win64.Wacatac.ns

Malware family: Wacatac

Wacatac malware demonstrates multiple malicious capabilities including data theft, system compromise, and secondary payload deployment. It can download additional malware components including ransomware to extend attack impact.
N/A
Detection Rate
6,231,056
File Size (bytes)
2023-12-31
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
eaca902c39d57b5db11495414536e183
SHA1
ee82e6647ed698b6ba2e0862d9cb4f74cef79191
SHA256
4938e8bdf87fbd17938c64c99056acb33d25183d3d724012bfd4e945ce91f814
SHA512
77476912039c068e51bbf5222fea5be4503511df92c1199b3f8ad1169b506aa4ca0f753a9538749749f2fbe16554dbbd0656342763f6861188e76d1fa18192bd
ImpHash
1cd069a1d0a6220306935daaf0c539a1

PE Analysis

Basic Information

Icon
Hash: ddea6aed184e5f40c47b4f8604799be3
Fuzzy: d8a0ba9ab3d18f8a88c48ff3a55f7629
dHash: 92e0b496a6cada72
Image Base 0x140000000
Entry Point 0x1409dfb00
Compilation Time 2023-06-28 16:22:06
Checksum 0x005fd019 (Actual: 0x005fd019)
OS Version 5.2
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 18 libraries
Exports 0 functions
Resources 7 Resources
Sections 12 Sections

Version Information

Comments
CompanyName Game repack
FileDescription Game Repack Install
FileVersion 9.0.0.1
LegalCopyright Game repack
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 733,992 bytes 391,585 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 30DC6DA5137775C96F9C50AF7A66B74A
0x000b5000 213,508 bytes 60,871 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9C1FBED48D570FCEFE8611DB59D48995
0x000ea000 37,152 bytes 761 bytes 7.62 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A13FF258F7A5DD7B8CEB07BAD92D424B
0x000f4000 28,488 bytes 16,774 bytes 7.75 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0456FAFC86A37C20165E303A88A7298D
0x000fb000 86,016 bytes 61,507 bytes 7.91 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D520B83BC23AFB1DB32AD707192723E4
0x00110000 2,676 bytes 1,795 bytes 7.73 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ C76FFF96AB5C449046C542583DEE5509
.imports 0x00111000 4,096 bytes 1,536 bytes 3.04 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6EBA0BAF26668511D94A8DACA83F245C
.tls 0x00112000 4,096 bytes 512 bytes 0.28 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BE9ECC3B1C03B51DC5E9DE84CB76674A
.rsrc 0x00113000 7,168 bytes 7,168 bytes 4.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D6242B0D550459CAED4D5E3102E27873
.themida 0x00115000 9,216,000 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x009df000 5,685,760 bytes 5,685,760 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ CA344B7F0D4479C0622BB0936B0603AA
.reloc 0x00f4c000 4,096 bytes 16 bytes 2.35 (Normal) IMAGE_SCN_MEM_READ 06647748C1D6FF391C1C728478307EF0
Entropy Analysis Alert

7 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 7 (6,492 bytes)
Resource Type Count Total Size Percentage
RT_ICON 4 4,640 bytes
71.5%
RT_GROUP_ICON 1 62 bytes
1%
RT_VERSION 1 772 bytes
11.9%
RT_MANIFEST 1 1,018 bytes
15.7%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Ransom.Win64.Wacatac.ns Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win64.Wacatac.ns without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware