ExcelDna IntelliSense xll Trojan Downloader File Malware Analysis: ea3220a72619730496031f4546f63cee
Gridinsoft Logo

ExcelDna.IntelliSense.xll Trojan Downloader Analysis

Technical Analysis

File Name ExcelDna.IntelliSense.xll
File Type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.229.174
Database Version 2025-11-26 10:00:25 UTC

Trojan.Win32.Downloader.cld

Malware family: Downloader

Downloader Trojans specialize in retrieving and installing additional malware payloads. Unlike comprehensive malware, they focus specifically on payload delivery rather than direct system damage.
N/A
Detection Rate
2,209,280
File Size (bytes)
2025-11-26
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
ea3220a72619730496031f4546f63cee
SHA1
37feeb0bfa5d1c651130543afec504db9c49089d
SHA256
c1761bd91852275ed317f14e0e66e7b90031663889958a6ff307a6c8c7320332
SHA512
b70a72eab197ee48452067527a2430d6e41359c77f7eb4edcc40da2b228d67421340cbcc453ed9a5a6bd65fee78181f85aecfc52dd272c47ad6eeef33a65c6b6
ImpHash
5064e065e7316209ae63e0766bddb8c4

PE Analysis

Basic Information

Image Base 0x10000000
Entry Point 0x10002ad7
Compilation Time 2021-03-21 21:48:28
Checksum 0x00000000 (Actual: 0x00220417)
OS Version 6.0
PEiD Signatures PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
PDB Path C:\Work\Excel-DNA\ExcelDna\Source\ExcelDna\Release\ExcelDna.pdb
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
KERNEL32, USER32, OLEAUT32
Exports 10014 functions
Resources 12 Resources
Sections 5 Sections

Version Information

Translation 0x0000 0x04b0
Comments
CompanyName Excel-DNA
FileDescription Excel-DNA IntelliSense Host
FileVersion 1.4.3.0
InternalName ExcelDna.IntelliSense.Host.dll
LegalCopyright Copyright © Excel-DNA Contributors 2013-2020
LegalTrademarks
OriginalFilename ExcelDna.IntelliSense.Host.dll
ProductName Excel-DNA IntelliSense
ProductVersion 1.4.3
Assembly Version 1.4.3.0
Comments Unmanaged loader shim for Excel-DNA Add-Ins
CompanyName Govert van Drimmelen
FileDescription Excel-DNA Dynamic Link Library
FileVersion 1.2.2.0
InternalName ExcelDna
LegalCopyright Copyright (C) 2005-2021 Govert van Drimmelen
OriginalFilename ExcelDna.xll
ProductName Excel-DNA Add-In Framework for Microsoft Excel
ProductVersion 1.2
Translation 0x0800 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 256,332 bytes 256,512 bytes 4.76 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ AE865A576F63498559BCC06088FB0ACD
.rdata 0x00040000 191,806 bytes 192,000 bytes 5.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B0EE728D1A8318828E1B1219A1BF8909
.data 0x0006f000 45,696 bytes 2,560 bytes 2.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B4DCF36DEC6E9D4D636C93AF683FFBB9
.rsrc 0x0007b000 1,730,880 bytes 1,731,072 bytes 5.28 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7CA6775E41E7B37520C4520FE281EF0D
.reloc 0x00222000 25,776 bytes 26,112 bytes 5.65 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ ED9D8E39037A157C8B72B4D70C6D9352

Resource Analysis

Total Resources: 12 (1,729,886 bytes)
Resource Type Count Total Size Percentage
ASSEMBLY 1 1,603,072 bytes
92.7%
ASSEMBLY_LZMA 3 112,153 bytes
6.5%
CONFIG 1 907 bytes
0.1%
DNA 1 644 bytes
0%
RT_STRING 4 10,126 bytes
0.6%
RT_VERSION 2 2,984 bytes
0.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Downloader.cld Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Downloader.cld without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware