Gridinsoft Logo

Non confirmé 250455.crdownload Trojan Packed Analysis

Technical Analysis

File Name Non confirmé 250455.crdownload
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.231.174
Database Version 2025-12-28 21:00:34 UTC

Trojan.Win64.Packed.cl

Malware family: Packed

Packed malware uses compression, encryption, or obfuscation techniques to alter code appearance and evade security detection. These methods modify the original malware structure to bypass signature-based detection systems and complicate analysis efforts.
N/A
Detection Rate
6,711,824
File Size (bytes)
2025-12-28
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b0914d647a3b6c303a86a894b1259248
SHA1
3698197a1ab8d731371c81354ae03fe4ce71fb6f
SHA256
9bfd22fbe424bb730df0f1fefd82932834cfca67176f749699bdd4bfe55534ff
SHA512
a34506beccd72b8bd5542e4a4ca54db221a609a1c7c63b7d6375a14e322fbf9642bd76e58dd2cdcc39210b1f0505ab501697998c94b093e7009af14d3c0d4232
ImpHash
6463e38e8581062b60ff809380300dbe

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x180d19058
Compilation Time 2025-02-27 23:04:47
Checksum 0x0066b305 (Actual: 0x0066b305)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 8 libraries
kernel32, CRYPT32, WS2_32, USER32, ADVAPI32, SHELL32, MSWSOCK, bcrypt
Exports 174 functions
Resources 27 Resources
Sections 14 Sections

Version Information

CompanyName CMD Softworks
FileDescription Dynamic Link Library for the Solara Utility
FileVersion 3.1.15.0
InternalName SOLARA
LegalCopyright Copyright © 2024 CMD Softworks
OriginalFilename SolaraV3.dll
ProductName Solara V3
ProductVersion 3.1.15.0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 5,686,412 bytes 2,365,952 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 62E39CA488B5220EEAC9112D3869C2E6
0x0056e000 1,332,454 bytes 484,352 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E9ED1821E76D2C25AA1FE36B95CAF5CB
0x006b4000 76,220 bytes 13,312 bytes 7.94 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1767EA51E1B5C90389E25DFAE521F989
0x006c7000 192,288 bytes 111,104 bytes 7.73 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 229639BF78FD9E9C6972F829F72DFA82
0x006f6000 500 bytes 512 bytes 4.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 99EA35B98823F236797042B2D6B614C2
0x006f7000 1,096 bytes 1,024 bytes 5.03 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 344D39943B26E29AE12724A78965612A
0x006f8000 48,396 bytes 26,624 bytes 7.85 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 4B1C0F8FA072418F428C1B989CC7ED2B
.edata 0x00704000 6,144 bytes 6,144 bytes 5.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A77D4BBCF31C8EC0B22CD8499BFBC040
.idata 0x00706000 4,096 bytes 1,024 bytes 2.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CD56ED77FE20261AA3773D6923720D53
.tls 0x00707000 4,096 bytes 512 bytes 0.27 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A3DD5451E93FE7230F64D82CDCF6AD91
.rsrc 0x00708000 8,704 bytes 8,704 bytes 4.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 70EAE3101897FB4AB93C247C8C2F976A
.themida 0x0070b000 6,348,800 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x00d19000 3,691,008 bytes 3,691,008 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7E380950689CAC5A364DE3235BBD885C
.reloc 0x0109f000 4,096 bytes 16 bytes 2.35 (Normal) IMAGE_SCN_MEM_READ DC26538C199F1419EB5458BBE7DBEFCE
Entropy Analysis Alert

6 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 27 (7,134 bytes)
Resource Type Count Total Size Percentage
RT_DIALOG 7 1,692 bytes
23.7%
RT_STRING 9 109 bytes
1.5%
RT_RCDATA 9 4,404 bytes
61.7%
RT_VERSION 1 784 bytes
11%
RT_MANIFEST 1 145 bytes
2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win64.Packed.cl Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.Packed.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware