Gridinsoft Logo

Libwinpthread-1.dll Trojan Sabsik Analysis

Technical Analysis

File Name libwinpthread-1.dll
File Type
PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
Scanner Version 1.0.228.174
Database Version 2025-10-25 18:00:15 UTC

Ransom.Win64.Sabsik.sa

Malware family: Sabsik

Sabsik is a malware variant capable of downloading additional payloads, including ransomware components. It can encrypt user files and initiate ransom demands. This threat represents a multi-stage attack where initial infection leads to more severe system compromise.
N/A
Detection Rate
2,306,048
File Size (bytes)
2025-10-25
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
ae371018618c09a57ce3d5501c4c7b28
SHA1
f77006a6638cd05b6b87370290d2d0435d810914
SHA256
7e57eb8d03967a9cbe42e24a621f4855ed57a6f9701c6ffa13806dfba46b52a8
SHA512
dacab0c7f566d7c6312e8546a076185a893aefead809d3eac9fc3126ed7387e3f97434b2e7d73b50b5b0d35ca78fa8032fb76fbadb62d862a9af759a4293e871
ImpHash
a4f0d1347d345de7c16f87077c75bfb6

PE Analysis

Basic Information

Image Base 0x2307a0000
Entry Point 0x2307a11f0
Compilation Time 2025-10-23 17:36:47
Checksum 0x0023ee60 (Actual: 0x0023ee60)
OS Version 4.0
PEiD Signatures PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 4 libraries
bcrypt, KERNEL32, msvcrt, USER32
Exports 156 functions
Resources 2 Resources
Sections 11 Sections

Version Information

CompanyName Solutions Future Corp
FileDescription Flow Maker
FileVersion 18.1.80.2664
InternalName mobile_ai_speed
LegalCopyright Copyright (C) 2021 Solutions Future Corp
OriginalFilename mobile_ai_speed.exe
ProductName Mobile AI Speed Accelerator
ProductVersion 18.1.80.2664
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 545,184 bytes 545,280 bytes 5.62 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 4F5F4B39B193F3350919F2E7A6BB4B52
.data 0x00087000 83,568 bytes 83,968 bytes 4.04 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5A9828439994A77662D3F6C42E791165
.rdata 0x0009c000 1,407,192 bytes 1,407,488 bytes 4.14 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E632A78DED889B1086AEE312D0CB409F
.pdata 0x001f4000 127,188 bytes 127,488 bytes 5.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 80DF4FC0EF2FF73F9F5797FAAD4028D5
.xdata 0x00214000 109,200 bytes 109,568 bytes 3.15 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FE8C000E9919298F496FF4297FD7BC7F
.bss 0x0022f000 2,880 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.edata 0x00230000 4,971 bytes 5,120 bytes 5.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BAF7EFCF4D8FE2BF70BF4B8F1CE33A26
.idata 0x00232000 3,032 bytes 3,072 bytes 4.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AE85743B25CCFBCB0706D4CE140C8F9F
.tls 0x00233000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x00234000 1,336 bytes 1,536 bytes 3.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DBABA0EF3DA0BBC35D84DA4DFDBA4926
.reloc 0x00235000 20,900 bytes 20,992 bytes 5.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8E7F36283C24CCF11B67178A62ABB104

Resource Analysis

Total Resources: 2 (1,171 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 836 bytes
71.4%
RT_MANIFEST 1 335 bytes
28.6%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Ransom.Win64.Sabsik.sa Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win64.Sabsik.sa without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware