Gridinsoft Logo
File Icon

Updater.exe Trojan Packed Analysis

Technical Analysis

File Name Updater.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.182.174
Database Version 2024-07-15 20:00:25 UTC
⚠

Trojan.Win64.Packed.sa

Malware family: Packed

Packed malware uses compression, encryption, or obfuscation techniques to alter code appearance and evade security detection. These methods modify the original malware structure to bypass signature-based detection systems and complicate analysis efforts.
N/A
Detection Rate
9,689,600
File Size (bytes)
2024-07-15
Analysis Date

Scan Another File

The uploaded file itself is not retained or shared with third parties. File names, hashes, and analysis results may appear in public reports. For confidential material, contact Support before uploading. How we use your data.

File Identification

Hash Type Value Action
MD5
4ab8ccecd4a134b37a1141b515371b66
SHA1
d0ebd671b85d91b7e4405e78dc8de723c23ee99d
SHA256
7059ff79287dcb1ead0d9b0a166bc551d729b1c7c412cecab3574ac1379685f8
SHA512
249ed30e142530b006958605f9f31f6d9fcf39b412e4ef1b2040887ed7020363749ce89150c4c35a3b4a92a7e6955775dc9f7c0246034fe18909c39bdb121ecd
ImpHash
5f85c353cf9895ecc2a751010283213a

PE Analysis

Basic Information

▼
Icon
Hash: 3baaa1348a74c805c98ca0c9ccd05c11
Fuzzy: 3d5004e5f1a3de5b86836ab7f3986200
dHash: f0cc9d93928ec8e0
Image Base 0x140000000
Entry Point 0x14087b511
Compilation Time 2024-06-29 13:47:42
Checksum 0x00000000 (Actual: 0x00946b87)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 4 libraries
msvcrt, KERNEL32, WTSAPI32, USER32
Exports 0 functions
Resources 3 Resources
Sections 10 Sections

Version Information

▼
CompanyName Google Inc.
FileTitle chrome.exe
FileDescription Google Chrome
FileVersion 70,0,3538,110
LegalCopyright Copyright 2017 Google Inc. All rights reserved.
LegalTrademark
ProductName Google Chrome
ProductVersion 70,0,3538,110
Translation 0x0409 0x04e4

PE Sections

▼
Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 74,358 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00014000 12,836 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x00018000 5,234,632 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.pdata 0x00516000 408 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.00cfg 0x00517000 16 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.tls 0x00518000 16 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.vmp0 0x00519000 3,496,420 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.vmp1 0x0086f000 9,618,824 bytes 9,618,944 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D4CC77FEF0D229CB27E192067596E7DA
.reloc 0x0119c000 228 bytes 512 bytes 2.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 75FFE5ACD12D6097E354066B18130975
.rsrc 0x0119d000 68,632 bytes 69,120 bytes 3.52 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9C37A4C754CC1206D5C4DAD67CE81970
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

▼
Total Resources: 3 (68,396 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 67,624 bytes
98.9%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 752 bytes
1.1%

Certificate Chain Analysis

▼
No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.Packed.sa Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.Packed.sa without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. 1
    Get Gridinsoft Anti-Malware — it's a quick 2 MB download that won't slow down your PC.
  2. 2
    Run the installer gsam-en-install.exe. The setup takes about 2 minutes and doesn't require a restart.
  3. 3
    The app launches right after installation. You'll see the main dashboard with the scan button front and center.
  4. 4
    Hit "Standard Scan" — this checks all the spots where malware typically hides: temp folders, browser data, startup programs, and system directories.
  5. 5
    Once the scan finds this threat, click "Clean Now". The removal usually happens instantly, though some stubborn infections may need a reboot.
  6. 6
    If you see a restart prompt, go ahead and reboot. This clears any malware that was running in memory and ensures your system starts fresh.
Important: Before You Start
Quick tip: unplug from the internet before scanning. Some malware phones home for instructions or downloads extra payloads when it senses trouble. If the infection is severe, boot into Safe Mode first — it limits what can run and makes cleanup easier.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware