在线病毒检测器 | v.1.0.178.174 |
数据库版本: | 2024-06-08 03:01:04 |
RedLine Stealer是一种恶意程序,旨在从浏览器、系统和已安装软件中窃取用户的机密数据。它通常通过电子邮件附件或被攻陷的网站传递。RedLine不仅窃取敏感信息,还通过引入其他恶意软件到受害者的操作系统中构成重大威胁。这种双重攻击方式使RedLine成为一个强大而危险的网络威胁。
File | AcrossSetup_2_30b.exe |
已检查 | 2024-06-08 00:43:54 |
MD5 | 013259e6c32bac59938e30086e88d27b |
SHA1 | 0edd41ec07d23608e3106e1f7bad485431ea9254 |
SHA256 | bb69aa08bdbcaa8860d26feaa036760b683f0e164fb18b5a772f0c4321e63b1d |
SHA512 | c5737f95aa15829c1fe433c92c9c837bb0c372e9c6863c6dd1cfbb80be3d6d9532196c7ef5992e29e3ab70918b395934bc4b5961c44845ccd5ceec858479d479 |
Imphash | bc70c4fa605f17c85050b7c7b6d42e44 |
File Size | 74492720 bytes |
Gridinsoft能够识别并消除Spy.Win32.Redline.lu!heur,无需进一步的用户干预。
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.9600.16428 (winblue_gdr.131013-1700) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.9600.16428 |
Translation | 0x0409 0x04b0 |
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 11.00.9600.16428 (winblue_gdr.131013-1700) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.9600.16428 |
Translation | 0x0412 0x04b0 |
18406f799bfc9ee737c69028fe1c0734 e555e06a276978c32ed8efbc4ad0084c b269ccaaaacc69b2 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x004067cc |
Compilation: | 2013-10-14 05:50:27 |
Checksum: | 0x0470bf45 (Actual: 0x0470bf45) |
OS Version: | 6.3 |
PDB Path: | wextract.pdb |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | OK |
Sections: | 5 |
Imports: | ADVAPI32, KERNEL32, GDI32, USER32, msvcrt, COMCTL32, Cabinet, VERSION, |
Exports: | 0 |
Resources: | 49 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000065cc | 0x00006600 | e9bf1a1e456a9a811b1b86e6602e3636 | 6.38 |
.data | 0x00008000 | 0x00001a8c | 0x00000400 | 317f8a934ee443eee01c2a315bde9ca1 | 3.18 |
.idata | 0x0000a000 | 0x00001078 | 0x00001200 | d8675ba112ef922c6057a02546757a1a | 5.05 |
.rsrc | 0x0000c000 | 0x046fc493 | 0x046fc600 | f7c465d24427c50ae31214587bdc76c5 | 8.00 |
.reloc | 0x04709000 | 0x000013ae | 0x00001400 | 83de2f9b2c95be6fea06bced7e8a058e | 3.72 |