在线病毒检测器 | v.1.0.176.174 |
数据库版本: | 2024-05-17 11:00:18 |
STOP/Djvu勒索软件,也简称为STOP勒索软件或Djvu勒索软件,是一种恶意软件,它加密受害者计算机上的文件,并要求赎金以解密这些文件。这种勒索软件变种已经活跃了数年,影响了众多用户和组织。
File | Moon |
已检查 | 2024-05-17 09:02:25 |
MD5 | f53c71e50af396778d6d94b7067b9613 |
SHA1 | 0f66ef86e34795b66c3620e81cfe64e4d3ab47b4 |
SHA256 | 717c20f1e4f5925c103b80832f80ab2079ca22d09df089dbf9d835ac0a1a63e9 |
SHA512 | 87ebefdfcee5e27a106a7fa9a4627fef2b36bc345d16ede48c2115cbc51a494a8825e5a6e073f4687777524f7c71e72ae6c95d54e5663ac1adfe5bf9e1623f71 |
Imphash | 8b14535b7546f94f1ac354dac2df7e48 |
File Size | 741376 bytes |
Gridinsoft能够识别并消除Ransom.Win32.STOP.tr,无需进一步的用户干预。
FileVersions | 70.75.12.64 |
InternalName | Moon |
FileDescription | Verens |
LegalCopyright | Copyrights (C) 2023, fulletien |
OriginalFilenames | Filezer |
ProductVersions | 82.1.74.60 |
Translation | 0x16fe 0x06d8 |
6d7c5a93bf831c241b0941dc53f8e085 f32a923f45a1742bd3257f9787651b6f 40dadac2a2928aa4 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00403f3c |
Compilation: | 2023-02-19 16:26:29 |
Checksum: | 0x000c32a8 (Actual: 0x000c32a8) |
OS Version: | 5.1 |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 4 |
Imports: | KERNEL32, USER32, GDI32, ole32, MSIMG32, |
Exports: | 0 |
Resources: | 20 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00010f93 | 0x00011000 | 50c3e9908b61c20baf11e0bb68117d81 | 6.71 |
.rdata | 0x00012000 | 0x00006e26 | 0x00007000 | e021289596833055eb00db85310a2431 | 4.70 |
.data | 0x00019000 | 0x003e8248 | 0x00093800 | bd21ede275e476fed6949abcf9252a61 | 7.98 |
.rsrc | 0x00402000 | 0x000093d0 | 0x00009400 | 038cedd2b93b2d0b1871fc4174e371e3 | 4.73 |