在线病毒检测器 | v.1.0.165.174 |
数据库版本: | 2024-02-21 17:00:25 |
STOP/Djvu勒索软件,也简称为STOP勒索软件或Djvu勒索软件,是一种恶意软件,它加密受害者计算机上的文件,并要求赎金以解密这些文件。这种勒索软件变种已经活跃了数年,影响了众多用户和组织。
File | Utsysc.exe |
已检查 | 2024-02-21 15:07:46 |
MD5 | ac0f0cfa391d0f2900ebebac08580118 |
SHA1 | f1236be60b85aa1e7f5264e4610e9ef1f192442a |
SHA256 | 2f7bc154ff7f15135f69a43f738760b3a45b677a36b734d3e9e0c1c7cd897849 |
SHA512 | 6f52d7300ada6b8f9a0c89d654931923821a478302ee273ffb3b62bd77a2af687d5ca23d98282b3ed64cd31b441d83301d19780c93c63cac7ff6303aef484c5a |
Imphash | 63fbd33cf4b705e9ce0b5af578a99fd8 |
File Size | 390144 bytes |
Gridinsoft能够识别并消除Ransom.Win32.STOP.tr!n,无需进一步的用户干预。
FileVersion | 96.56.50.43 |
FileDescription | Second |
OriginalFilename | Space |
ProductName | Tube |
ProductVersion | 22.16.40.61 |
Translation | 0x040a 0x0671 |
9bd3c06975da7957a1b81260f99cd4be b2b51230aab611a32292ed3db5d4ab6c e0e4eaeaeae2e4ea |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00402399 |
Compilation: | 2023-07-16 11:12:09 |
Checksum: | 0x0006b492 (Actual: 0x0006b492) |
OS Version: | 5.0 |
PDB Path: | C:\hehigubafeh-45_fehu\23-togiliyefuc\vot zofucolumumip\r.pdb |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 4 |
Imports: | KERNEL32, USER32, ADVAPI32, ole32, WINHTTP, |
Exports: | 0 |
Resources: | 18 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0004caa9 | 0x0004cc00 | f93f82eec80110fea526c697fe84330c | 7.79 |
.rdata | 0x0004e000 | 0x00005344 | 0x00005400 | 854e5f8da4f86f2ec0d9b4bbe3208576 | 5.82 |
.data | 0x00054000 | 0x00012424 | 0x00005200 | 96a451139b3fce7dbfc960f647b9c07e | 1.24 |
.rsrc | 0x00067000 | 0x00009d88 | 0x00007e00 | 320426522d72ba3b5c76ffd08cf38396 | 4.73 |