在线病毒检测器 | v.1.0.176.174 |
数据库版本: | 2024-05-22 12:00:30 |
Shellcode 是一种恶意代码形式,旨在在受感染的计算机上执行,促使恶意软件的启动或下载其他恶意软件。它通常作为网络攻击的初始步骤,使受感染的系统更容易受到进一步的攻击。
File | meterpreter1.exe |
已检查 | 2024-05-22 09:59:22 |
MD5 | e98826a6639642d49e19ca33b6a6d369 |
SHA1 | 496ef176b55b420927a801430e5980d7e3815737 |
SHA256 | 58b75e58e8951274e951ad926e0d650810de58b0110bb9d21dde677ec64d8c08 |
SHA512 | 62a2cb5c7532b7e92c1ea9ce250274166fc6b0780065139bae370c0b53e578a26b1eba3f184a49ef8b49a24d3efd7f08ec32f6a6b8eddd3d8ec24ed5dd40458d |
Imphash | b4c6fff030479aa3b12625be67bf4914 |
File Size | 7168 bytes |
Gridinsoft能够识别并消除Trojan.Win64.ShellCode.sd!s1,无需进一步的用户干预。
Image Base: | 0x140000000 |
Entry Point: | 0x140004000 |
Compilation: | 2010-04-14 22:06:53 |
Checksum: | 0x00007535 (Actual: 0x000076ed) |
OS Version: | 4.0 |
PEiD: | PE32+ executable (GUI) x86-64, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 3 |
Imports: | KERNEL32, |
Exports: | 0 |
Resources: | 0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000104e | 0x00001200 | a4a5deae25708a9e05f50bcad7075c86 | 0.17 |
.rdata | 0x00003000 | 0x00000084 | 0x00000200 | 253b88122c36b6951090c6288183e4ae | 0.96 |
.fpnu | 0x00004000 | 0x00000278 | 0x00000400 | fa6553dffc10d2b81be71fbc60d43234 | 4.29 |