文件名 | LunaDepths_Setup_1.0.0.exe |
文件类型 |
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
|
扫描器版本 | 1.0.217.174 |
数据库版本 | 2025-05-31 07:00:20 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
182c204bdf0eec8e17d5a9bceb2a8161
|
|
SHA1 |
707ac94428f979359348f1194b939587d1101753
|
|
SHA256 |
b36d23299f77c310438e2026320b2157359fd5cd6cc69bcca7934a288282c2eb
|
|
SHA512 |
e758fce950e4c50d14198d2ca38edc73e2e4803afc744b29fcf71974e91a4ea7ebf348651964b2b5dff843f2dff7e862921437185522f9bd8e4ad129e3f32e66
|
|
ImpHash |
6b04c59e943668a55caa2198f68c5386
|
图标 |
哈希: f6afd44498557e81e889d841b60d77d1
模糊: 7dabbabe91017a3458aa24982fc15da5 dHash: 8033332b2b130f80 |
映像基址 | 0x140000000 |
入口点 | 0x1400013d0 |
编译时间 | 2025-05-27 20:08:30 |
校验和 | 0x0273f634 (实际: 0x0273557e) |
操作系统版本 | 4.0 |
PEiD 签名 |
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
|
数字签名 | The expected hash does not match the digest in SpcInfo |
导入 | 20 库 |
导出 | 0 函数 |
资源 | 4 资源 |
节 | 10 节 |
CodePage | 0409 |
FileSubtype | 0x00000000 |
FileFlagsExMask | 0x00000000 |
InternalName | loader.exe |
ProductVersion | 01.00.00.00 |
FileDescription | Myth Game Download Loader |
Charset | 0409 |
FileVersion | 01.00.00.00 |
Type | Application |
ProductName | Myth Game Download Loader |
OriginalFilename | loader.exe |
FileFlagsEx | 0x00000000 |
FileOS | 0x00000004 |
FileFlags | 0x00000000 |
LegalCopyright | © Myth Corporation. All rights reserved. |
CompanyName | Myth Corporation |
Language | 0409 |
Translation | 0x0000 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
9,587,760 bytes | 9,588,224 bytes | 5.66 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
188B357ECE3720FE73101C59897F9987 |
.data |
0x00926000 |
5,808 bytes | 6,144 bytes | 0.96 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D96EF008EB27C23EEDC0DD5C14201C03 |
.rdata |
0x00928000 |
30,218,040 bytes | 30,218,240 bytes | 7.96 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
ECDD10258CC96494C0734A38220234B0 |
.pdata |
0x025fa000 |
718,848 bytes | 718,848 bytes | 6.68 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
56770668F5DFA5A9C486FCA6AEAA4B4F |
.xdata |
0x026aa000 |
510,416 bytes | 510,464 bytes | 3.12 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
52B44B130DEDCD5885EEDBE3FFDBE71B |
.bss |
0x02727000 |
1,088 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x02728000 |
15,164 bytes | 15,360 bytes | 4.67 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
FB9F713831E76799F25F90817C9757E9 |
.tls |
0x0272c000 |
16 bytes | 512 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BF619EAC0CDF3F68D496EA9344137E8B |
.rsrc |
0x0272d000 |
6,944 bytes | 7,168 bytes | 4.50 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
11ABDF8170116B5074C05FF80934D6B9 |
.reloc |
0x0272f000 |
35,664 bytes | 35,840 bytes | 5.51 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
C3F5D04096BC63169642CE99C541D98E |
1 检测到高熵(≥7.5)的节 - 可能存在打包/加密
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 1 | 4,264 字节 | |
RT_GROUP_ICON | 1 | 20 字节 | |
RT_VERSION | 1 | 1,240 字节 | |
RT_MANIFEST | 1 | 1,107 字节 |
产品 | Myth Game Download Loader |
描述 | Myth Game Download Loader |
文件版本 | 01.00.00.00 |
原始名称 | loader.exe |
验证状态 | The digital signature of the object did not verify. |
签名者 | RIDEV YAZILIM SİSTEMLERİ LTD ŞTİ; Sectigo Public Code Signing CA EV R36; Sectigo Public Code Signing Root R46; Sectigo (AAA) |
内部名称 | loader.exe |
版权 | © Myth Corporation. All rights reserved. |
48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
33 D7 08 A8 91 40 53 19 E2 A5 BB D3 39 B9 AD 6E
29 5A F1 11 A9 E1 80 67 5A 33 5D F9 E6 48 53 6E
✓ 此文件已进行数字签名,证书链已验证。
The expected hash does not match the digest in SpcInfo
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要