在线病毒检测器 | v.1.0.179.174 |
数据库版本: | 2024-06-19 21:00:29 |
STOP/Djvu勒索软件,也简称为STOP勒索软件或Djvu勒索软件,是一种恶意软件,它加密受害者计算机上的文件,并要求赎金以解密这些文件。这种勒索软件变种已经活跃了数年,影响了众多用户和组织。
File | Lariavts |
已检查 | 2024-06-19 18:40:20 |
MD5 | f52f4f70eea35c76b61d25998a3fc800 |
SHA1 | 9ecf5616851cf0c35cfef9047e5d873ff3106017 |
SHA256 | bc59e033df4fb938c03ffaf274aba1a639efb5163cf84a4fc5beb6026e562dcf |
SHA512 | 8f2f4661cc2fccfe23ee99e8f453cd756800704ee9e0830b1d43ef216e0c1b8e8d9414df86ad10a9a52d7678319ff3b7ccd4cc2efb533f0c730f0c919c0cb086 |
Imphash | 9ddb1fabeee3b3905613cd98d52e8a73 |
File Size | 215552 bytes |
Gridinsoft能够识别并消除Ransom.Win32.STOP.dd!se45814,无需进一步的用户干预。
OriginalFilename | Lariavts |
ProductsVersion | 21.59.2.52 |
ProdeuctionVersion | 25.50.25.70 |
Translation | 0x28ae 0x0e7e |
14d7e34b02f46e4dec36816d716deebc bdff42d6c84a72fabe5e6a9e7d584b5a bcf9f6f2e0c4ebf4 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x0040308f |
Compilation: | 2022-08-01 21:51:17 |
Checksum: | 0x00037320 (Actual: 0x00037320) |
OS Version: | 5.0 |
PDB Path: | C:\nicaziwic.pdb |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 4 |
Imports: | KERNEL32, USER32, GDI32, ADVAPI32, |
Exports: | 0 |
Resources: | 21 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00024002 | 0x00024200 | 2e3d3e39e9bc5be42a26215b55746d12 | 7.39 |
.rdata | 0x00026000 | 0x0000322a | 0x00003400 | 06537fe23959d431b74909ad65a4ec6d | 5.20 |
.data | 0x0002a000 | 0x004206f8 | 0x00001800 | 0df8a594e674ea3d2654b17e17e2654a | 3.22 |
.rsrc | 0x0044b000 | 0x0000b6e8 | 0x0000b800 | 7a5ed2a0913143ed287d87d9c10956ae | 4.13 |