文件名 | ED2025E.exe |
文件类型 |
Win32 EXE
|
魔术字节 | PE32 executable (GUI) Intel 80386, for MS Windows |
SSDEEP 哈希 |
196608:R49e7DcO0ks0LKjwdlpTtPiinn3eZJdH9iA8wXs5RycvZRmM/crJt:n7NKj2TB1nnefHZ8TYGZd8
|
扫描器版本 | 1.0.223.174 |
数据库版本 | 2025-08-12 17:00:16 UTC |
被 23 个安全引擎检测到 - 需要谨慎
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
17e257ae3841673f6e7bb2df5963b623
|
|
SHA1 |
9d10910010ca4173e4fbd91c87ade6ecef495d63
|
|
SHA256 |
257406be54dbe033b1fa8741b17469d09f3903759bd89eac078055e05c43de53
|
|
SHA512 |
2fdb496e2debceccf4bfa31fbcba217c2dac7fb51bc10f7d186e2f2aaa63e64dfdc5fefad46b88fbb0c622cfeaa9059feb9366892dffc736b589ddefa942069a
|
|
ImpHash |
027b956eb1692abba9fb0aa5d1ab6ebe
|
图标 |
哈希: fff17d1f98e8fb7732809c105f0ce82f
模糊: cae0ae3b9e66a01bff52f8b80fe26656 dHash: f3c31b1333272c20 |
映像基址 | 0x00400000 |
入口点 | 0x021b0a48 |
编译时间 | 2025-08-08 15:30:47 |
校验和 | 0x00000000 (实际: 0x00eeb373) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
数字签名 | No valid SignedData structure was found. |
导入 | 17 库 |
导出 | 2 函数 |
资源 | 279 资源 |
节 | 14 节 |
FileDescription | ED2025E |
FileVersion | 7.0.1.132 |
ProgramID | com.embarcadero.ED2025E |
ProductName | ED2025E |
ProductVersion | 1.0.0.0 |
Translation | 0x0409 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
|
0x00001000 |
8,888,320 bytes | 3,236,352 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
25C52E1873D04EEBE0357E00A7015D9C |
|
0x0087b000 |
36,864 bytes | 14,848 bytes | 7.98 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
22F119061AB46B0CB40277A02F8D5EAF |
|
0x00884000 |
180,224 bytes | 88,064 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9F1F6945C6B7FDD23D19460EFFB066C3 |
|
0x008b0000 |
667,648 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x00953000 |
20,480 bytes | 512 bytes | 2.60 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
F83E7B36DDB0B5111E480A68E7A90FE3 |
|
0x00958000 |
28,672 bytes | 6,656 bytes | 7.83 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6A6A0A8C8D5CBF9C7053BDBD5F8653D2 |
|
0x0095f000 |
4,096 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x00960000 |
4,096 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x00961000 |
4,096 bytes | 512 bytes | 1.52 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A2C9BAB72509D24D42CF7639BB03A726 |
|
0x00962000 |
671,744 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x00a06000 |
9,760,768 bytes | 5,222,912 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
3AA776F7C547F734CBC53B5B1606481F |
.rsrc |
0x01355000 |
253,952 bytes | 250,368 bytes | 3.92 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
863174D954674CB32A3C1852BF382C1F |
|
0x01393000 |
7,962,624 bytes | 4,113,408 bytes | 7.99 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
31D6B79D8114B48E6698CDF1BBF3965E |
.data |
0x01b2b000 |
2,662,400 bytes | 2,661,376 bytes | 7.98 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
DA563B2069896C531A7DF6D9BF64F120 |
7 检测到高熵(≥7.5)的节 - 可能存在打包/加密
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
UNICODEDATA | 6 | 191,535 字节 | |
VCLSTYLE | 36 | 4,096,605 字节 | |
RT_CURSOR | 11 | 3,388 字节 | |
RT_BITMAP | 30 | 13,464 字节 | |
RT_ICON | 6 | 108,404 字节 | |
RT_DIALOG | 2 | 164 字节 | |
RT_STRING | 107 | 122,454 字节 | |
RT_RCDATA | 67 | 5,202,150 字节 | |
RT_GROUP_CURSOR | 11 | 220 字节 | |
RT_GROUP_ICON | 1 | 90 字节 | |
RT_VERSION | 1 | 504 字节 | |
RT_MANIFEST | 1 | 1,803 字节 |
产品 | ED2025E |
描述 | ED2025E |
文件版本 | 7.0.1.132 |
57 15 3D A1 24 2E 12 7E 0F 62 18 CC 08 22 F3 CC
25 AD 5A E6 8C 38 AD 10 21 08 6F 4F FC 8B A4 70
✓ 此文件已进行数字签名,证书链已验证。
No valid SignedData structure was found.
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要