文件名 | CLDeanon.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.179.174 |
数据库版本 | 2024-06-14 17:00:18 UTC |
恶意软件家族: Heuristic
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
89ec08f06ab3a48b17461901a840e728
|
|
SHA1 |
a5aace8bb6e64b0cc03624d0ee67ad9ecc191b18
|
|
SHA256 |
4e043542639b4aa669ead0bafe18c865d250e60b376fdfc3249a12b1d30586a1
|
|
SHA512 |
b4a349d96d15699adfe9a00ae27a982ef49783b4c14713e081a1b964fbbc78f3aafe2dc65a041b2c571ebecc0f5e40f43ba0f77e290fd6472154d5d7bf3018ec
|
|
ImpHash |
7104476aa32cf4b45f58ce5b636dd82a
|
映像基址 | 0x00400000 |
入口点 | 0x004011ea |
编译时间 | 2023-10-24 10:27:33 |
校验和 | 0x00000000 (实际: 0x01a09f75) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB 路径 | C:\A10\m82f1\output.pdb |
数字签名 | The expected hash does not match the digest in SpcInfo |
导入 |
2 库
USER32, KERNEL32 |
导出 | 0 函数 |
资源 | 0 资源 |
节 | 8 节 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
706,132 bytes | 706,560 bytes | 5.74 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
215F39379CB16FDBA41E9606C0571CD2 |
.rdata |
0x000ae000 |
113,961 bytes | 114,176 bytes | 4.07 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A1A3F26FD3AB0C1C5744B2B900AFF343 |
.data |
0x000ca000 |
20,752 bytes | 12,800 bytes | 3.75 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
839BC5887C318D2AC557DA071AC1E0D9 |
.idata |
0x000d0000 |
4,892 bytes | 5,120 bytes | 4.77 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6872CA9F08F8F0BF4BFC532607518962 |
.111 |
0x000d2000 |
170,923 bytes | 171,008 bytes | 6.39 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
156982D1D7CB861E2E32D6627FC6AE7A |
.tls |
0x000fc000 |
777 bytes | 1,024 bytes | 0.01 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
C573BD7CEA296A9C5D230CA6B5AEE1A6 |
.00cfg |
0x000fd000 |
270 bytes | 512 bytes | 0.11 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0D11B4C081005B4BF744A5A3F51C1A2F |
.reloc |
0x000fe000 |
24,182 bytes | 24,576 bytes | 6.10 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
E6887E57B3B1CBB23F5126CDFD518992 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
The expected hash does not match the digest in SpcInfo
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁