Gridinsoft Logo
File Icon

PDFConverter32.exe Trojan Heuristic Analysis

Technical Analysis

File Name PDFConverter32.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.219.174
Database Version 2025-07-03 13:00:27 UTC

Trojan.Heur!.02256021

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
96,900,936
File Size (bytes)
2025-07-03
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
61d64aa0a2d81d3ac7a1d10724b923a6
SHA1
6565f39264851cacda8548a3d59f97d5f2504dc1
SHA256
78922df6086a0eef17ace252bab55e1ce4e24199d9d466e7bc3671af5828c262
SHA512
b20c8cab060225e3589a039b46258deb676d41dedabfcfa01bf9d1a376869de5b2c6a475f06db99781000038a35482cc8c7a557802e232e59d967a37e3a9960f
ImpHash
58e187dd0c4a66f42b06a97a6787dd6c

PE Analysis

Basic Information

Icon
Hash: a6a75a64e8377a90bd4bf0ee7d82c5f5
Fuzzy: c12591ea90d17f2ff71e03b31f50815f
dHash: 1cfa5ac8a6a0a4a4
Image Base 0x00400000
Entry Point 0x038b6061
Compilation Time 2025-07-02 07:53:42
Checksum 0x05c6ab06 (Actual: 0x05c6a8ea)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 31 libraries
Exports 3 functions
Resources 1558 Resources
Sections 13 Sections

Version Information

CompanyName Softplicity
FileDescription PDF Converter
FileVersion 6.5.0.350
ProductVersion 6.5
ProgramID com.embarcadero.PDFConverter
ProductName PDFConverter
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 44,244,852 bytes 44,244,992 bytes 6.57 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 99D22BF5B14331B37953131A7237F302
.itext 0x02a33000 190,808 bytes 190,976 bytes 5.77 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 0C410EF6288D2ABDEB7A024F1C3B97C8
.data 0x02a62000 1,194,116 bytes 1,194,496 bytes 6.63 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6D83A1BC7381B7F05A5C09B593C3FDD2
.bss 0x02b86000 2,510,656 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x02deb000 47,918 bytes 48,128 bytes 5.59 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3BAA0475915CD9C77B765F1B71B2E754
.didata 0x02df7000 31,274 bytes 31,744 bytes 5.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A0116ABAEDE9CF70E24F2ED17F85B92D
.edata 0x02dff000 161 bytes 512 bytes 2.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 54E1F5A9FFA09AF6EC62313779EAC6D5
.tls 0x02e00000 1,628 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x02e01000 93 bytes 512 bytes 1.42 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8FBB749BF945FB7BBBF259F779F632B3
.emptyR 0x02e02000 3,024,592 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.vmp0 0x030e5000 3,022,955 bytes 3,023,360 bytes 7.79 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2B6F61AF99119808A99D1F4C30A84DEB
.vmp1 0x033c8000 2,033,648 bytes 2,033,664 bytes 7.66 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 70862240BB68A5F5373C2A1FCD571550
.rsrc 0x035b9000 46,120,960 bytes 46,119,424 bytes 7.56 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 928D06E1DCBE09FE0614D2ABEE2EFA54
Entropy Analysis Alert

3 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 1558 (46,021,504 bytes)
Resource Type Count Total Size Percentage
UNICODEDATA 6 191,535 bytes
0.4%
VCLSTYLE 1 36,941 bytes
0.1%
RT_CURSOR 119 81,404 bytes
0.2%
RT_BITMAP 158 99,608 bytes
0.2%
RT_ICON 9 21,864 bytes
0%
RT_DIALOG 15 4,174 bytes
0%
RT_STRING 370 296,648 bytes
0.6%
RT_RCDATA 777 45,284,877 bytes
98.4%
RT_GROUP_CURSOR 97 2,220 bytes
0%
RT_GROUP_ICON 4 150 bytes
0%
RT_VERSION 1 588 bytes
0%
RT_MANIFEST 1 1,495 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.02256021 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.02256021 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware