在线病毒检测器 | v.1.0.153.174 |
数据库版本: | 2023-12-29 21:01:50 |
RedLine Stealer是一种恶意程序,旨在从浏览器、系统和已安装软件中窃取用户的机密数据。它通常通过电子邮件附件或被攻陷的网站传递。RedLine不仅窃取敏感信息,还通过引入其他恶意软件到受害者的操作系统中构成重大威胁。这种双重攻击方式使RedLine成为一个强大而危险的网络威胁。
File | Zipware-14-OCT-2018-V160.exe |
已检查 | 2023-12-29 19:38:37 |
MD5 | 6ca55c007ce8fbac283ed4d03e2303b9 |
SHA1 | 6c3246bf1a65416a9de4676bebc12854ba6741f7 |
SHA256 | 0abd67edd302610c2f17419320c6a53dc1f441807e45e87b0c974d34ee6c3053 |
SHA512 | 38873ab04a5b327b3d8a0850445911622f6c6ec3698c0729c6e8c8be9bd4a31c63e7f406401ef4e83e4c9d33699ecfd60ced43122a5c3622d3d7a4927125a6e4 |
Imphash | bc70c4fa605f17c85050b7c7b6d42e44 |
File Size | 3381616 bytes |
Gridinsoft能够识别并消除Spy.Win32.Redline.lu!heur,无需进一步的用户干预。
DigiCert SHA2 Assured ID Code Signing CA | Bazwise Technology (AU) |
DigiCert Assured ID Root CA | DigiCert Inc (US) |
验证 | OK |
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.9600.16428 (winblue_gdr.131013-1700) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.9600.16428 |
Translation | 0x0409 0x04b0 |
b4e35fab514a0ca7b15815d7b9e0ef39 de7054b46a4aa933e23a31b431ec5c79 e862e2b26a6ab2ec |
|
Image Base: | 0x00400000 |
Entry Point: | 0x004067cc |
Compilation: | 2013-10-14 05:50:27 |
Checksum: | 0x0033ba0b (Actual: 0x0033ba0b) |
OS Version: | 6.3 |
PDB Path: | wextract.pdb |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | OK |
Sections: | 5 |
Imports: | ADVAPI32, KERNEL32, GDI32, USER32, msvcrt, COMCTL32, Cabinet, VERSION, |
Exports: | 0 |
Resources: | 36 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000065cc | 0x00006600 | e9bf1a1e456a9a811b1b86e6602e3636 | 6.38 |
.data | 0x00008000 | 0x00001a8c | 0x00000400 | 317f8a934ee443eee01c2a315bde9ca1 | 3.18 |
.idata | 0x0000a000 | 0x00001078 | 0x00001200 | d8675ba112ef922c6057a02546757a1a | 5.05 |
.rsrc | 0x0000c000 | 0x0032e74f | 0x0032e800 | 5bf9b1bea95fd8181f0d8e12e7689f2b | 8.00 |
.reloc | 0x0033b000 | 0x000013ae | 0x00001400 | 83de2f9b2c95be6fea06bced7e8a058e | 3.72 |