File Name | Evony_ZZIwjL-iRQg.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.222.174 |
Database Version | 2025-08-08 15:00:42 UTC |
Malware family: Gen
Hash Type | Value | Action |
---|---|---|
MD5 |
dba533edfe91246318f3baa8e2efa47a
|
|
SHA1 |
63e0789a8169ee6f1f58e0562feb41aad9d24591
|
|
SHA256 |
5a31e3fe32f6c77525512f701a4b321432050b99d2772b6556efb361fa28c71e
|
|
SHA512 |
26639c83fbc575c0438857117c97f21bb58b0066789878b405cf2ab1eb1da410ab9e595cc84cc41a4d95fd0cafb2874e7696cdb69f7c8ee565e982715babe7df
|
|
ImpHash |
f6c9c6f772dfe2649a84a6db922c00aa
|
Icon |
Hash: 8c4101387ee28cf51fb8ada80a8eb61c
Fuzzy: 284caa1ccbccdb039a1579d6bfb75c53 dHash: 1f6b5bdbf33373d3 |
Image Base | 0x00400000 |
Entry Point | 0x00453ddc |
Compilation Time | 2023-06-08 10:14:39 |
Checksum | 0x0012fdcb (Actual: 0x0012fdcb) |
OS Version | 6.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | G:\Evony\Src\trunk\client\TopLoader\Release\Evony_AABBCCDDEEF.pdb |
Digital Signature | OK |
Imports |
9 libraries
WLDAP32, KERNEL32, USER32, GDI32, ADVAPI32, SHELL32, ole32, WS2_32, bcrypt |
Exports | 0 functions |
Resources | 10 Resources |
Sections | 5 Sections |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
483,743 bytes | 483,840 bytes | 6.56 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
CD2553C8FE6180A2AD621D8F9FC826E5 |
.rdata |
0x00078000 |
91,952 bytes | 92,160 bytes | 5.73 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
09C40821E94D427D353DDBF258538840 |
.data |
0x0008f000 |
7,236 bytes | 3,584 bytes | 2.90 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9937DCCAD262ED00B33097C25B5FE33C |
.rsrc |
0x00091000 |
588,600 bytes | 588,800 bytes | 7.24 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
77C377545EC59FAC8CA207AA83CD6612 |
.reloc |
0x00121000 |
18,484 bytes | 18,944 bytes | 6.64 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
A2FB2BB4B44BE015C32AAD948A5D5548 |
3 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_BITMAP | 3 | 519,416 bytes | |
RT_ICON | 1 | 67,624 bytes | |
RT_MENU | 1 | 80 bytes | |
RT_DIALOG | 1 | 284 bytes | |
RT_STRING | 1 | 68 bytes | |
RT_ACCELERATOR | 1 | 16 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_MANIFEST | 1 | 392 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Trojan.Win32.Gen.ca without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system