Gridinsoft Logo
File Icon

Uploaded Trojan Heuristic Analysis

Technical Analysis

File Name uploaded
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.139.174
Database Version 2023-09-22 17:02:44 UTC

Trojan.Heur!.02052023

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
9,080,320
File Size (bytes)
2023-09-22
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a3dae7bffce2e4ab11fe69bb66d0559c
SHA1
035d147cbbe7c172bfebd57f3738ccab0182c650
SHA256
effeee653ee42dbb987274fe3d7947a83d99e8325d8b3e37f9a90966b8558702
SHA512
f52b3917fbe876a50709db835a710a677e9585b3c55a3565f960e13bac30e8c7d1c68e564865b7851593f4387f164c4dfef95224f95f74b732f6e24ff95a49c7
ImpHash
bdb8209e92517b05c0d878e59e377155

PE Analysis

Basic Information

Icon
Hash: b9cf7ea8ef13311c3d117c1c4aed2f39
Fuzzy: d5b6bc51135c2d59beb995c723d4a090
dHash: 71f0f0f0f0f0f0f0
Image Base 0x140000000
Entry Point 0x1401dd794
Compilation Time 2023-08-01 07:36:05
Checksum 0x00000000 (Actual: 0x008ad52e)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path E:\Jenkins\workspace\8.1_PS_Release_master\paleoscanproduct\bin\ps_ow_connect.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 50 libraries
Exports 52 functions
Resources 9 Resources
Sections 9 Sections

Version Information

CompanyName Eliis
FileDescription PaleoScan - A Breakthrough in Seismic Interpretation
FileVersion 1.8.0.0
InternalName PaleoScan
LegalCopyright Copyright © 2017
OriginalFilename PaleoScan.exe
ProductName PaleoScan
ProductVersion 1.8.0.0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,138,087 bytes 2,138,112 bytes 6.42 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ E45DF97B17D88901F19017E9A04EEB3D
.textidx 0x0020b000 608,693 bytes 608,768 bytes 6.10 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6F3CD906CDA2F359B5CF2BB01AEC87FD
.rdata 0x002a0000 5,980,956 bytes 5,981,184 bytes 7.27 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5A27D019E9DDF5ECD13F3AA4607D85A3
.data 0x00855000 103,096 bytes 72,704 bytes 4.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 28EC4329F8823530CA5E6095AA578AF5
.pdata 0x0086f000 110,100 bytes 110,592 bytes 6.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EF349428DA6D215CB0A7F195443A275A
.fnp_dir 0x0088a000 120 bytes 512 bytes 0.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 38AF43D61A4127D1EEA12B4AE15C6786
.fnp_mar 0x0088b000 1 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0088c000 143,496 bytes 143,872 bytes 7.19 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B7726C47E8B22321B9D758004D5690CD
.reloc 0x008b0000 23,040 bytes 23,040 bytes 5.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ E0C49BA81007463D9D0EA3BA41BD3A18
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 9 (142,905 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 141,421 bytes
99%
RT_GROUP_ICON 1 90 bytes
0.1%
RT_VERSION 1 756 bytes
0.5%
RT_MANIFEST 1 638 bytes
0.4%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.02052023 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.02052023 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware