在线病毒检测器 | v.1.0.143.174 |
数据库版本: | 2023-10-23 02:07:07 |
Amadey是一种强大的Windows信息窃取威胁,以其持久性机制、模块化设计和执行各种恶意任务的能力而闻名。它通常通过钓鱼电子邮件或恶意下载方式侵入系统。一旦进入系统,Amadey可以捕获敏感信息,如登录凭据、个人数据和财务详情。其模块化结构允许威胁行为者自定义其功能,使其成为网络犯罪武器中的多功能工具。
File | Wextract |
已检查 | 2023-10-23 00:39:07 |
MD5 | 0e4cce351d50179ad135e2f12a52e9fb |
SHA1 | 47a8a4562b95f29a273f7df4371149887e5ba238 |
SHA256 | 362d8f8fcc698554a750a5dfb1e261eb3b5442fb4bfe4746c8ba9431ec944305 |
SHA512 | b8bbfb06c8c096d0c2a4930bae1ecc971eeab792064acf5a75c7dca27f918bf5828e92313d84a27b4ccd0793e34d3c49a0af29cbab8398b0a03e215ea62dd0e0 |
Imphash | 646167cce332c1c252cdcb1839e0cf48 |
File Size | 620032 bytes |
Gridinsoft能够识别并消除Trojan.Win32.Amadey.bot,无需进一步的用户干预。
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.17763.1 (WinBuild.160101.0800) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.17763.1 |
Translation | 0x0409 0x04b0 |
3e91cc67e146308239c15a39134ff14e 2e2cf0d16805fb9dfdfc9b2658485b99 f0f0f4d8c8c8d8f0 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00406a60 |
Compilation: | 2022-05-24 22:49:06 |
Checksum: | 0x000a2652 (Actual: 0x000a2652) |
OS Version: | 10.0 |
PDB Path: | wextract.pdb |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 5 |
Imports: | ADVAPI32, KERNEL32, GDI32, USER32, msvcrt, COMCTL32, Cabinet, VERSION, |
Exports: | 0 |
Resources: | 43 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00006314 | 0x00006400 | b0b66b32f4ca82e2e157c51b24da0be7 | 6.31 |
.data | 0x00008000 | 0x00001a48 | 0x00000200 | 7b9890a93c0516bb070e1170cfde54d5 | 4.97 |
.idata | 0x0000a000 | 0x00001052 | 0x00001200 | 67ce48bf2e7c8fe3321ca7aa188f77e2 | 5.03 |
.rsrc | 0x0000c000 | 0x0008f000 | 0x0008f000 | 311eae3b221ab17e543d0be3fbcec4e3 | 7.90 |
.reloc | 0x0009b000 | 0x00000888 | 0x00000a00 | 6025c825c4098ef081ac8ee3c8d5dd22 | 6.22 |