Gridinsoft Logo

The slinky_loader.exe File Analysis

Technical Analysis

File Name slinky_loader.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (console) x86-64, for MS Windows
SSDEEP Hash
393216:EjAPfF3dNPVLCEDLQzH2ciIrHW4H//o3Mdg9R1gPBw6:QAjLCEDLQzkIL7/wUg5gPBw6
Scanner Version 1.0.216.174
Database Version 2025-05-12 19:00:23 UTC

Suspicious File Detected

Detected by 28 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
39%
Detection Rate
88,048,261
File Size (bytes)
28/71
Engines Detected
2025-05-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
296cfc072f4a07c9d199543558f5af0d
SHA1
c51b8c42d2260b55909e75bc34be778a5dc0a0f1
SHA256
4a89f6dcece114c5eaac94ecb07f15e1eb7adfdad5bac2ea8b3f7752ff8f104c
SHA512
d72fa950964c5c26c1021d48ead743a79bf805d21a9e3c7dc64f2f5f2a77932f69e9d24017504679a4f587c093edda2bcbbf35fb9d9a24ec57068799a98cee26
ImpHash
1861bc6d7cdbc03b4f60bf54c0a672fe

Security Engines with Detections (28 of 71)

Bkav
W64.AIDetectMalware Malicious
Lionic
Trojan.Win32.GenericKDQ.4!c Malicious
MicroWorld-eScan
QD:Trojan.GenericKDQ.26EA376385 Malicious
CAT-QuickHeal
Trojan.Ghanarava.1738055106f5af0d Malicious
Skyhigh
Artemis Malicious
Zillya
Trojan.Agent.Script.1640764 Malicious
Sangfor
PUP.Win32.Agent.Vbiz Malicious
BitDefender
QD:Trojan.GenericKDQ.26EA376385 Malicious
Symantec
Infostealer Malicious
Cynet
Malicious (score: 99) Malicious
Kaspersky
UDS:DangerousObject.Multi.Generic Malicious
Avast
FileRepMalware [Misc] Malicious
Emsisoft
QD:Trojan.GenericKDQ.26EA376385 (B) Malicious
F-Secure
Trojan.TR/Redcap.aemph Malicious
VIPRE
QD:Trojan.GenericKDQ.26EA376385 Malicious
McAfeeD
ti!4A89F6DCECE1 Malicious
CTX
exe.trojan.aemph Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
GData
QD:Trojan.GenericKDQ.26EA376385 Malicious
Varist
W64/ABApplication.HLEX-4468 Malicious
Avira
TR/Redcap.aemph Malicious
Arcabit
QD:Trojan.GenericQ.26EA376385 Malicious
Microsoft
PUA:Win32/Packunwan Malicious
Google
Detected Malicious
ALYac
QD:Trojan.GenericKDQ.26EA376385 Malicious
MaxSecure
Trojan.Malware.221463327.susgen Malicious
AVG
FileRepMalware [Misc] Malicious
DeepInstinct
MALICIOUS Malicious
43 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140009b24
Compilation Time 2021-10-14 21:08:02
Checksum 0x00f1ae8c (Actual: 0x054076c8)
OS Version 5.2
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 2 libraries
KERNEL32, ADVAPI32
Exports 0 functions
Resources 1 Resources
Sections 7 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 144,208 bytes 144,384 bytes 6.47 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ DCD00CD1AF6A00DACFBE21D1C168CF6B
.rdata 0x00025000 70,564 bytes 70,656 bytes 5.74 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 2DE7F93B07553CCF57DB41EA6C7E25D1
.data 0x00037000 66,456 bytes 3,584 bytes 1.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 93FF6BEAB5249602FDB56E41214C93A1
.pdata 0x00048000 7,644 bytes 7,680 bytes 5.35 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5FD73E6B132F697D173A19E8AB0209EB
_RDATA 0x0004a000 244 bytes 512 bytes 1.95 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0506636A835BF6907171A92F4541D21E
.rsrc 0x0004b000 1,600 bytes 2,048 bytes 5.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 227286F5FF4696CFB0559CE0E96C8077
.reloc 0x0004c000 1,868 bytes 2,048 bytes 5.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7918CD7FE09E2D60657C15AADE4BA826

Resource Analysis

Total Resources: 1 (1,509 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 1,509 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
28 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware