Gridinsoft Logo
File Icon

RiddleJoker.exe Trojan Downloader Analysis

Technical Analysis

File Name RiddleJoker.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.212.174
Database Version 2025-04-09 05:00:57 UTC

Trojan.Win32.Downloader.cld

Malware family: Downloader

Downloader Trojans specialize in retrieving and installing additional malware payloads. Unlike comprehensive malware, they focus specifically on payload delivery rather than direct system damage.
N/A
Detection Rate
4,471,808
File Size (bytes)
2025-04-09
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b9a86e8d1fbf5a92119007e055ad53dc
SHA1
5237f7723570e965071c945012138cbe61edb066
SHA256
adc923e2e27ebb15a41a1e5a70de34275be9ecb2c613491e61f4d3b96f2c2dab
SHA512
a86660931b438175bc75b42599d4df6e1b9d333833d9791b3f40284182704eb1578cfe75d637321ee2e0bd4757294c612d14fd5f9bf1e8c712a3a7160c8543ee
ImpHash
9567e2dba4e003d705d55f3641eaa38e

PE Analysis

Basic Information

Icon
Hash: b7c9a633688259186695b644c08a7708
Fuzzy: 02b188445a4469d7b5b77c796a9095f3
dHash: f8c0c294b392d033
Image Base 0x00400000
Entry Point 0x0063b053
Compilation Time 2017-11-30 11:41:37
Checksum 0x00451024 (Actual: 0x00451024)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path tvpwin32.pdb
Digital Signature No valid SignedData structure was found.
Imports 13 libraries
Exports 0 functions
Resources 66 Resources
Sections 6 Sections

Version Information

FileDescription RIDDLE JOKER
FileVersion 1.2.0.3
InternalName tvp2/win32
LegalCopyright (KIRIKIRI core) (C) W.Dee and contributors All Rights Reserved. This software is based in part on the work of Independent JPEG Group. For details: Run this program with '-about' option.
OriginalFilename tvpwin32.exe
ProductName TVP(KIRIKIRI) Z core / Scripting Platform for Win32
ProductVersion 1.2.0.3
Translation 0x0411 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,875,392 bytes 2,873,344 bytes 6.67 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 1E6428883876AA901ECD3F2CCDCBEC6D
.adata 0x002bf000 4,096 bytes 1,536 bytes 3.86 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 829658B5DC4F0FCD5C975D52F9EC439E
.rdata 0x002c0000 970,752 bytes 968,704 bytes 6.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0A83FB06CB826EB2197E8CCF0492ED09
.data 0x003ad000 700,416 bytes 41,472 bytes 5.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 91B99CB7F4B95243F68256046C25B14D
.rsrc 0x00458000 277,917 bytes 278,016 bytes 6.95 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DF64DFC71F2C31D7B2A66815A5A10A50
.reloc 0x0049c000 311,296 bytes 307,712 bytes 3.75 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D81E063300FF1F88600808BF119CFB04
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 66 (275,142 bytes)
Resource Type Count Total Size Percentage
TEXT 3 105,827 bytes
38.5%
RT_ICON 4 101,272 bytes
36.8%
RT_DIALOG 2 752 bytes
0.3%
RT_STRING 54 65,592 bytes
23.8%
RT_GROUP_ICON 1 62 bytes
0%
RT_VERSION 1 1,056 bytes
0.4%
RT_MANIFEST 1 581 bytes
0.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Downloader.cld Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Downloader.cld without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware