Gridinsoft Logo

LiGRbS9th4jeux.exe Trojan Heuristic Analysis

Technical Analysis

File Name liGRbS9th4jeux.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.219.174
Database Version 2025-07-05 12:00:29 UTC

Trojan.Heur!.02212023

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
26,175,488
File Size (bytes)
2025-07-05
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
f3cf488603823d85817924925b26f736
SHA1
c3823d375e81e02ff148f235d9c013cf08e03d5f
SHA256
ce48479109a1f97b65164aa52bb6be5b3611e6ee0cdd7bd960be13101bc2c6aa
SHA512
40815eca4dcb0b8830204ce809535d8ee54b5677e5b70dd4a5346d5555fefe33bb93a15f16d7b92301e96e7510e162e24ee1fea6fe7643057313a24bb47050a5
ImpHash
dc503039c29d358680591eff958d78fd

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x14260fa2d
Compilation Time 2024-04-21 12:47:42
Checksum 0x00000000 (Actual: 0x018ff114)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 16 libraries
Exports 0 functions
Resources 1 Resources
Sections 13 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 7,366,870 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00708000 6,381,892 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x00d1f000 1,464,080 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.pdata 0x00e85000 152,448 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.00cfg 0x00eab000 56 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.gxfg 0x00eac000 12,880 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.retplne 0x00eb0000 140 bytes 0 bytes 0.00 (Normal) 0x00000000 D41D8CD98F00B204E9800998ECF8427E
.tls 0x00eb1000 9 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
_RDATA 0x00eb2000 348 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
. [3 0x00eb3000 10,047,415 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.;I9 0x01848000 312 bytes 512 bytes 1.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B77D87F1537D03A84A76342D0FCAEAD0
.G>0 0x01849000 26,173,376 bytes 26,173,440 bytes 7.92 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 8FF0A4732C218E3E48F1E3E7FBFABDD6
.rsrc 0x0313f000 422 bytes 512 bytes 4.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1257811DFB6A37AAB96111F86A1CBEF2
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 1 (334 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 334 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.02212023 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.02212023 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware