Gridinsoft Logo
File Icon

Evony_ZZIwjL-iRQg.exe Trojan Gen Analysis

Technical Analysis

File Name Evony_ZZIwjL-iRQg.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.222.174
Database Version 2025-08-08 15:00:42 UTC

Trojan.Win32.Gen.ca

Malware family: Gen

This is a generic detection identifier for files exhibiting Trojan horse characteristics. It indicates malware that disguises itself as legitimate software while containing malicious code designed to compromise system security or steal information.
N/A
Detection Rate
1,198,952
File Size (bytes)
2025-08-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
dba533edfe91246318f3baa8e2efa47a
SHA1
63e0789a8169ee6f1f58e0562feb41aad9d24591
SHA256
5a31e3fe32f6c77525512f701a4b321432050b99d2772b6556efb361fa28c71e
SHA512
26639c83fbc575c0438857117c97f21bb58b0066789878b405cf2ab1eb1da410ab9e595cc84cc41a4d95fd0cafb2874e7696cdb69f7c8ee565e982715babe7df
ImpHash
f6c9c6f772dfe2649a84a6db922c00aa

PE Analysis

Basic Information

Icon
Hash: 8c4101387ee28cf51fb8ada80a8eb61c
Fuzzy: 284caa1ccbccdb039a1579d6bfb75c53
dHash: 1f6b5bdbf33373d3
Image Base 0x00400000
Entry Point 0x00453ddc
Compilation Time 2023-06-08 10:14:39
Checksum 0x0012fdcb (Actual: 0x0012fdcb)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path G:\Evony\Src\trunk\client\TopLoader\Release\Evony_AABBCCDDEEF.pdb
Digital Signature OK
Imports 9 libraries
WLDAP32, KERNEL32, USER32, GDI32, ADVAPI32, SHELL32, ole32, WS2_32, bcrypt
Exports 0 functions
Resources 10 Resources
Sections 5 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 483,743 bytes 483,840 bytes 6.56 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ CD2553C8FE6180A2AD621D8F9FC826E5
.rdata 0x00078000 91,952 bytes 92,160 bytes 5.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 09C40821E94D427D353DDBF258538840
.data 0x0008f000 7,236 bytes 3,584 bytes 2.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9937DCCAD262ED00B33097C25B5FE33C
.rsrc 0x00091000 588,600 bytes 588,800 bytes 7.24 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 77C377545EC59FAC8CA207AA83CD6612
.reloc 0x00121000 18,484 bytes 18,944 bytes 6.64 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A2FB2BB4B44BE015C32AAD948A5D5548
Entropy Analysis Alert

3 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 10 (587,900 bytes)
Resource Type Count Total Size Percentage
RT_BITMAP 3 519,416 bytes
88.4%
RT_ICON 1 67,624 bytes
11.5%
RT_MENU 1 80 bytes
0%
RT_DIALOG 1 284 bytes
0%
RT_STRING 1 68 bytes
0%
RT_ACCELERATOR 1 16 bytes
0%
RT_GROUP_ICON 1 20 bytes
0%
RT_MANIFEST 1 392 bytes
0.1%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

OK

Trojan.Win32.Gen.ca Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Gen.ca without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware