文件名 | CudoMiner.exe |
文件类型 |
Win32 EXE
|
魔术字节 | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive |
SSDEEP 哈希 |
24576:KbZgOflTcS7Mr6dU7rsoEDOr7S9ji4NVjK4HX7CspPIWx+:KbZgoMW3omOi9jHN9KM7CKPIB
|
扫描器版本 | 1.0.224.174 |
数据库版本 | 2025-09-09 20:00:56 UTC |
被 35 个安全引擎检测到 - 需要谨慎
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
e3082028116b8dc0c19446f223cd6c44
|
|
SHA1 |
0cccfea92f34ffb45897036549d1359a316013e2
|
|
SHA256 |
b6a16a9794c048b191274fb2ab9d8489497074df1ba278ba984ac7b507b03ae3
|
|
SHA512 |
98d609daa49ea81e0bafb48f2b632bf983163a23c09e21d8446d58c14d6c70f6afbfd2abf508f57862cea286539d8b3355a5cac49ab68a5030c4c6e299e32428
|
|
ImpHash |
eb0806dae800674e97000f10e2ec3aa2
|
图标 |
哈希: 3e10b6b366ef428e3bad1c3421bdb15d
模糊: 14a2c821702ba3b415275d1e0a54b509 dHash: f096aa4d49b296f0 |
映像基址 | 0x00400000 |
入口点 | 0x004042e6 |
编译时间 | 2020-08-29 19:32:12 |
校验和 | 0x000f4e05 (实际: 0x000f4e05) |
操作系统版本 | 4.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive
|
数字签名 | Chain verification from CN=Cudo Ventures\, Ltd., O=Cudo Ventures\, Ltd., ST=Dorset, C=GB, businessCategory=Private Organization, jurisdictionOfIncorporationCountryName=GB, serialNumber=11065412 (serial:118766608540164905958007824795681012614, sha1:7bb211d4b1cfee805e8dd7f8ce290665cdfa3b11) failed: The path could not be validated because the end-entity certificate expired 2024-08-09 23:59:59Z |
导入 |
7 库
ADVAPI32, COMCTL32, GDI32, KERNEL32, ole32, SHELL32, USER32 |
导出 | 0 函数 |
资源 | 8 资源 |
节 | 7 节 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
36,732 bytes | 36,864 bytes | 6.09 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES
|
1E58FE90B13D350FD5D26B9288F1487B |
.data |
0x0000a000 |
232 bytes | 512 bytes | 1.50 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES
|
A78502EA0EAE96A3084679427F64CAB6 |
.rdata |
0x0000b000 |
29,752 bytes | 30,208 bytes | 7.21 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES
|
6DDE0BC09ACA0747DAB0B4618D16CB86 |
.bss |
0x00013000 |
152,032 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x00039000 |
4,984 bytes | 5,120 bytes | 5.37 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
BF333CD621E6990C9EE35906DB406569 |
.ndata |
0x0003b000 |
90,112 bytes | 512 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
BF619EAC0CDF3F68D496EA9344137E8B |
.rsrc |
0x00051000 |
31,344 bytes | 31,744 bytes | 7.78 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES
|
877376B9A248E6E6FD8ADE7F13C9A70D |
1 检测到高熵(≥7.5)的节 - 可能存在打包/加密
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 1 | 28,318 字节 | |
RT_DIALOG | 5 | 1,412 字节 | |
RT_GROUP_ICON | 1 | 20 字节 | |
RT_MANIFEST | 1 | 1,074 字节 |
验证状态 | A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. |
签名者 | Cudo Ventures, Ltd.; Sectigo Public Code Signing CA EV R36; Sectigo Public Code Signing Root R46; Sectigo (AAA) |
48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
33 D7 08 A8 91 40 53 19 E2 A5 BB D3 39 B9 AD 6E
59 59 9D E5 2B 1B 41 3E CE 67 5F C1 26 D9 BB 86
✓ 此文件已进行数字签名,证书链已验证。
Chain verification from CN=Cudo Ventures\, Ltd., O=Cudo Ventures\, Ltd., ST=Dorset, C=GB, businessCategory=Private Organization, jurisdictionOfIncorporationCountryName=GB, serialNumber=11065412 (serial:118766608540164905958007824795681012614, sha1:7bb211d4b1cfee805e8dd7f8ce290665cdfa3b11) failed: The path could not be validated because the end-entity certificate expired 2024-08-09 23:59:59Z
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要