文件名 | Xeno.dll |
文件类型 |
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
扫描器版本 | 1.0.226.174 |
数据库版本 | 2025-09-27 18:00:18 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
72b53ab6e85b1371823b34043d7fd638
|
|
SHA1 |
d1dfca71c1a31f5ced3e246b2029bc80dd5ad129
|
|
SHA256 |
bb64f7567bc3685a2514fc72a4f18f887e081addee1ff9264d6501207cb7d43f
|
|
SHA512 |
9cb65a2730521fc1a5592cb89b877d2500b024ec4895167530d623d9fa9c850e5d8aced49045a407be96c0213e2fb42705dac369fd35f5068a5243262295c8d0
|
|
ImpHash |
02a9b31076a31cec9aabeff2f49e3c6d
|
映像基址 | 0x180000000 |
入口点 | 0x18015af60 |
编译时间 | 2025-09-12 02:54:21 |
校验和 | 0x001c0c6c (实际: 0x001c0c6c) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
PDB 路径 | C:\Users\rizve\OneDrive\Desktop\Projects\Xeno\build\Release\net8.0-windows8.0\Xeno.pdb |
数字签名 | Chain verification from CN=Rizve A (serial:69584778256418573733429029698563849372, sha1:c32930d30686f298659124b96be5653cceb6d1fb) failed: The X.509 certificate provided is self-signed - "Common Name: Rizve A" |
导入 | 20 库 |
导出 | 6 函数 |
资源 | 2 资源 |
节 | 6 节 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
1,449,687 bytes | 1,449,984 bytes | 6.47 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
1F2227901A5966B68B9E1395D8312DF5 |
.rdata |
0x00163000 |
246,100 bytes | 246,272 bytes | 5.42 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E5C66D62E0146F76257B9DE8D58E11F3 |
.data |
0x001a0000 |
253,828 bytes | 30,208 bytes | 4.50 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
90366809978D9562F45B5DEA20732721 |
.pdata |
0x001de000 |
55,404 bytes | 55,808 bytes | 6.17 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
5B2AE022B0E238DBA3B3D694942B7385 |
.rsrc |
0x001ec000 |
27,640 bytes | 27,648 bytes | 7.99 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D2CE873557C81846636609A5F973A936 |
.reloc |
0x001f3000 |
5,936 bytes | 6,144 bytes | 5.38 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
D01D5661AC0D42AF8E219042EB74393F |
1 检测到高熵(≥7.5)的节 - 可能存在打包/加密
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_MANIFEST | 1 | 381 字节 | |
None | 1 | 27,093 字节 |
签名日期 | 02:59 AM 09/12/2025 (17 天前) |
验证状态 | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. |
签名者 | Rizve A |
34 59 8A 72 A3 AE EA B8 4A C8 BD 75 D4 71 BC 9C
A4 29 3B 6E 1E DD D7 A7 34 08 87 AD 7A 4E B7 24
7A 23 AE DA 53 69 96 0F 91 C8 3E 5C F4 C7 E3 3F
36 C2 B0 BD 7C 1B 3A E7 A3 B3 DD 36 CB C9 75 68
✓ 此文件已进行数字签名,证书链已验证。
Chain verification from CN=Rizve A (serial:69584778256418573733429029698563849372, sha1:c32930d30686f298659124b96be5653cceb6d1fb) failed: The X.509 certificate provided is self-signed - "Common Name: Rizve A"
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要