Gridinsoft Logo

Set-up.exe Trojan Sabsik Analysis

Technical Analysis

File Name Set-up.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.217.174
Database Version 2025-05-31 03:00:23 UTC

Ransom.Win64.Sabsik.sa

Malware family: Sabsik

Sabsik is a malware variant capable of downloading additional payloads, including ransomware components. It can encrypt user files and initiate ransom demands. This threat represents a multi-stage attack where initial infection leads to more severe system compromise.
N/A
Detection Rate
1,655,296
File Size (bytes)
2025-05-31
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
7815a46ec8ea124371481d7568ad55e8
SHA1
7715b5ffac394ad2fa30ab2fb868c248b03da391
SHA256
e3235b7d84b22ebdf6ce6ba4782df1208d502cdc5c8b2e5f9e8bfa83a7f6018e
SHA512
da34c6278c5b3af1f62613360ddad7bdb47a34c7603005e6bbdd6dcd7ace5d7b107acdf6cb285e216f69b1e2cba3b152fb393fcdc706813c6b2ca7425bf8ab4e
ImpHash
bb36df4412e03dad091fc4f040871a65

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1400aa4e0
Compilation Time 2025-05-29 18:27:33
Checksum 0x00000000 (Actual: 0x0019e766)
OS Version 6.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 1 libraries
KERNEL32
Exports 0 functions
Resources 0 Resources
Sections 11 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 835,998 bytes 836,096 bytes 6.96 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 54B83C326A8DE1B9D1CCC6C8D0358D01
.rdata 0x000ce000 68,244 bytes 68,608 bytes 4.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 50CC52696120AFF2E27434703C657032
.data 0x000df000 23,976 bytes 9,216 bytes 3.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6EA9CC52358017F13D0ACCC0E582FCD2
.pdata 0x000e5000 15,096 bytes 15,360 bytes 5.79 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B570B121E195352E3CFE3CE6734E947E
.gxfg 0x000e9000 8,256 bytes 8,704 bytes 5.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DEB86CF65F400106C3155B49B8A4672C
.retplne 0x000ec000 140 bytes 512 bytes 1.05 (Normal) 0x00000000 8C950F651287CBC1296BCB4E8CD7E990
.tls 0x000ed000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
_RDATA 0x000ee000 500 bytes 512 bytes 4.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ F3FEED136121FBC6E8F132772EBD1621
.reloc 0x000ef000 2,832 bytes 3,072 bytes 5.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ A4D6C90F58D41639AECF921AD379223F
.can 0x000f0000 355,328 bytes 355,328 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9009DA785D18019EAA2770BB1641D210
.can 0x00147000 355,328 bytes 355,328 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9009DA785D18019EAA2770BB1641D210
Entropy Analysis Alert

2 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Ransom.Win64.Sabsik.sa Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win64.Sabsik.sa without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware