Gridinsoft Logo

AlrisitService.exe Trojan Alructisit Analysis

Technical Analysis

File Name AlrisitService.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.184.174
Database Version 2024-08-08 19:00:18 UTC

Trojan.Win64.Alructisit.dd!c

Malware family: Alructisit

N/A
Detection Rate
68,745,856
File Size (bytes)
2024-08-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
2ea393cf8fe6f80e74c221dcd434896c
SHA1
06a21c14a331b38bc07937f24a34699525d1cac0
SHA256
7bcaa3ecd98573190bb24c427bb226d93ba728fc1ea9fdbdef904f43b2c795b1
SHA512
ce22f41dc41caf2d6b00a51f28e089b9bce7707b968afc5ae829fe0bbbbf284dcdcd758a530030f550c2e54f9a6d1d1a8fd05878da1414ce14f834e535204fca
ImpHash
f9c151e126be67f87f3b2ed5937cd491

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1402134c0
Compilation Time 2024-07-12 11:21:12
Checksum 0x00392eb1 (Actual: 0x04195bff)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature Unknown certificate revision 48293
Imports 19 libraries
Exports 1 functions
Resources 2 Resources
Sections 6 Sections

Version Information

FileDescription Alrisit Service
FileVersion 1.7.7.1
InternalName Alrisit Service
OriginalFilename AlrisitService
ProductVersion 1.7.7.1
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,398,542 bytes 2,398,720 bytes 6.42 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ AD25C24F28835FD1BA544542F02AA014
.rdata 0x0024b000 1,187,122 bytes 1,187,328 bytes 5.86 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 53E0C8DEC62A99074E332F4F7939703A
.data 0x0036d000 70,112 bytes 53,248 bytes 4.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE AE91D65DF11DEBAF867FBEEE8F2BBF4B
.pdata 0x0037f000 78,708 bytes 78,848 bytes 6.23 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E737A184A84DC83FD7EF386506FEAF89
.rsrc 0x00393000 2,424 bytes 2,560 bytes 4.95 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1F68724D01DF78EF6650D57CEF112B3B
.reloc 0x00394000 10,328 bytes 10,752 bytes 5.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ B94DD483B0A78F5940E1016728D5C442

Resource Analysis

Total Resources: 2 (2,258 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 528 bytes
23.4%
RT_MANIFEST 1 1,730 bytes
76.6%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

Unknown certificate revision 48293

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.Alructisit.dd!c Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.Alructisit.dd!c without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware