单文件制作_x64.exe Trojan Sabsik Analysis

Trojan Sabsik
Updated on 2024-05-24 (23 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.177.174
DB Version:2024-05-24 11:00:22

Ransom.Win64.Sabsik.sa

The Sabsik virus is capable of downloading additional malware onto your computer, which can encrypt your files and demand a ransom payment for their restoration. This virus is one of the ransomware variants, making it particularly dangerous for your data security.

File单文件制作_x64.exe
Checked2024-05-24 08:40:06
MD53f1da7dedb1290524a11d5979e150874
SHA1de5c66a176726d94006e365d101d7d9a71e08732
SHA256ad58f4febf7780bb453904477d57e90d341b8c385cabeeff7fba039473603e22
SHA512f70ba53a175548a9f2e1e46bec79cc9e30e2e229074b18e7ce18e01d8fb489e080a1651c3c4bcf747dac9d03abbba30a29a209e0c82e1dd85b1ade2665b5ffb4
Imphashc57e4f526395288c8406444b38b1e657
File Size4623521 bytes

Ransom.Win64.Sabsik.sa Removal

Ransom.Win64.Sabsik.sa Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win64.Sabsik.sa without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Comments
ProductVersion7.0.2.3822
LegalTrademarksmefcl;
Special Build
PrivateBuild
CompanyNameJexChan
FileDescriptionJexChan-PYG-JL-mefcl
FileVersion7.0.2.3822
InternalNameSimple packaging tool
LegalCopyrightCopyright ? 2012 - 2024 JexChan jl
OriginalFilenameSpackaging.exe
ProductNameSimple packaging tool
Translation0x0804 0x03a8

Portable Executable Info

f097373971afc98faf9573e9a9cfd9eb
84cf9457c9643a3d8daa59df67c5d7cf
6574f29e8e8e8e8e
Image Base:0x140000000
Entry Point:0x140c2e3e0
Compilation:2023-04-22 09:11:23
Checksum:0x0047250b (Actual: 0x004765e8)
OS Version:5.2
PEiD:MS-DOS executable PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, MZ for MS-DOS
Sign:The PE file does not contain a certificate table.
Sections:3
Imports: KERNEL32, SHLWAPI, USER32, GDI32, ADVAPI32, SHELL32, OLEAUT32, VERSION, SETUPAPI,
Exports: 18
Resources:33

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.MPRESS1 0x00001000 0x00c2d000 0x00456200 478ff53444294f8b520c774003b53764 8.00
.MPRESS2 0x00c2e000 0x00000eda 0x00001000 42f803343ddae4523e525bffaa0bc40f 5.86
.rsrc 0x00c2f000 0x0001163c 0x00011800 a8e54c59b4be102f9f5ac8528c2b1424 5.21

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware