文件名 | svchost.exe |
文件类型 |
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
|
扫描器版本 | 1.0.172.174 |
数据库版本 | 2024-04-18 18:00:28 UTC |
恶意软件家族: Packed
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
255850326fc8149ad7e635403c2de2bf
|
|
SHA1 |
0a4e6c76b7dab7ba445c1c0644c66f8579876200
|
|
SHA256 |
a761634b9327e17ea3330bb3ea6977f4d95e3c972f46d972a90b33d49739f5c4
|
|
SHA512 |
15e262bb018e56e0d65f1271263e612a85783d7f820d29379f5c1bdede59aacd76a119de61220be500ac60319b7f45abaaae917970aad86f1a0784b2df91ecec
|
|
ImpHash |
4d8a465943edbfae7c3166b9af900360
|
图标 |
哈希: f976ca290892cdb98cba4f6b0ff69089
模糊: be3977b5a702e9c4f9fcc82194460771 dHash: 2c9cb83cbcd8f472 |
映像基址 | 0x140000000 |
入口点 | 0x144b63144 |
编译时间 | 2023-06-25 21:41:03 |
校验和 | 0x03d5ef3d (实际: 0x02671212) |
操作系统版本 | 4.0 |
PEiD 签名 |
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
|
数字签名 | The PE file does not contain a certificate table. |
导入 | 13 库 |
导出 | 41 函数 |
资源 | 5 资源 |
节 | 16 节 |
CompanyName | D0kt0r Solutions |
FileDescription | SRBMiner-MULTI |
FileVersion | 2.3.0 |
LegalCopyright | 2023 D0kt0r |
ProductName | SRBMiner-MULTI |
ProductVersion | 2.3.0 |
Translation | 0x0000 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
|
0x00001000 |
13,209,600 bytes | 3,462,656 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D2A21419993C8453DCD61505A49E4A7D |
|
0x00c9a000 |
45,056 bytes | 4,096 bytes | 7.60 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
32C74BC41B6BD9D484D771EF0342CE46 |
|
0x00ca5000 |
48,615,424 bytes | 31,250,432 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
4515BFC5430B04DF463065C6E7F757AD |
|
0x03b02000 |
1,691,648 bytes | 493,056 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6ABA2902EC2BFE5139946009389636D0 |
|
0x03c9f000 |
159,744 bytes | 97,280 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
14D32C690BEEABD2460208D849701F70 |
|
0x03cc6000 |
561,152 bytes | 126,976 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
91F02DB02DE36BD447CCB3C38858A1B2 |
|
0x03d4f000 |
81,920 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_64BYTES
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d63000 |
4,096 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d64000 |
24,576 bytes | 512 bytes | 3.01 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
ECD01ACF1F6931E81CBEC79DB5D22EC8 |
|
0x03d6a000 |
4,096 bytes | 512 bytes | 0.76 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
087E0BF61EDF0720F5812AFDC3B0F7FF |
|
0x03d6b000 |
4,096 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d6c000 |
8,192 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d6e000 |
20,480 bytes | 5,632 bytes | 7.67 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
192475E5B80632748E02354745D9AE58 |
.rsrc |
0x03d73000 |
8,192 bytes | 6,144 bytes | 4.43 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
DEEBDAA8FE2AE069C537D68AE3A194AA |
|
0x03d75000 |
11,677,696 bytes | 1,887,232 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
248DE35446412BEA163FCF0D9465300D |
|
0x04898000 |
2,949,120 bytes | 2,948,608 bytes | 7.96 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A802D56649BAB5170A8C861B037E7448 |
9 检测到高熵(≥7.5)的节 - 可能存在打包/加密
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 2 | 3,600 字节 | |
RT_GROUP_ICON | 1 | 34 字节 | |
RT_VERSION | 1 | 576 字节 | |
RT_MANIFEST | 1 | 1,167 字节 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
The PE file does not contain a certificate table.
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁