文件名 | DigitalPulseService.exe |
文件类型 |
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
|
扫描器版本 | 1.0.158.174 |
数据库版本 | 2024-02-02 08:00:38 UTC |
恶意软件家族: Gen
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
93ee86cc086263a367933d1811ac66aa
|
|
SHA1 |
73c2d6ce5dd23501cc6f7bb64b08304f930d443d
|
|
SHA256 |
4de2f896ff1ff1c64d813cad08b92c633be586141d2d5c24099ae2ae4194bece
|
|
SHA512 |
d980e01e3f6a262016f3335a2d127f6efa6a73fe166f4f36355e439cbb2098d624e63ecd0ee8be8575b3aeefb0b1e9bc8e0552d65c4e611bff9f7f119c186c5a
|
|
ImpHash |
9cbefe68f395e67356e2a5d8d1b285c0
|
映像基址 | 0x00400000 |
入口点 | 0x00465580 |
编译时间 | 1970-01-01 00:00:00 |
校验和 | 0x00a021b7 (实际: 0x00a021b7) |
操作系统版本 | 6.1 |
PEiD 签名 |
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
|
数字签名 | OK |
导入 |
1 库
kernel32 |
导出 | 0 函数 |
资源 | 0 资源 |
节 | 6 节 |
AAA Certificate Services | Sectigo Limited (GB) |
Sectigo Public Code Signing Root R46 | Sectigo Limited (GB) |
Sectigo Public Code Signing CA R36 | Digital Pulse (US) |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
4,923,055 bytes | 4,923,392 bytes | 6.08 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
6EA99A93403DF119E34237AD71476826 |
.rdata |
0x004b3000 |
5,073,088 bytes | 5,073,408 bytes | 5.58 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0D1C90B3E213814A1B7BF31B4FD6A90E |
.data |
0x0098a000 |
752,072 bytes | 348,160 bytes | 5.11 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
3767B747F4B0840A219D23BC88D7242F |
.idata |
0x00a42000 |
1,148 bytes | 1,536 bytes | 3.58 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
DFCBAFBF43FC77FE82406C86C19674AF |
.reloc |
0x00a43000 |
94,580 bytes | 94,720 bytes | 5.45 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
2B015F55EAF4AE9A48B8F3186CC4D484 |
.symtab |
0x00a5b000 |
4 bytes | 512 bytes | 0.02 (正常) |
IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
07B5472D347D42780469FB2654B7FC54 |
主题 |
Sectigo Public Code Signing Root R46 Sectigo Limited GB |
颁发者 | AAA Certificate Services |
序列号 | 97015870309959729927281967672979788822 |
主题 |
Sectigo Public Code Signing CA R36 Sectigo Limited GB |
颁发者 | Sectigo Public Code Signing Root R46 |
序列号 | 130417131954583740712891216934480190474 |
主题 |
Digital Pulse Digital Pulse US |
颁发者 | Sectigo Public Code Signing CA R36 |
序列号 | 162539329929736495350243538513345262963 |
OK
按照以下步骤完全从系统中移除威胁