文件名 | Launcher.exe |
文件类型 |
Win32 EXE
|
魔术字节 | PE32+ executable (console) x86-64, for MS Windows |
SSDEEP 哈希 |
24576:U4N6y2BvYlZjBuCk6QOo0xwq1+bP/kjDfYXIwRtm/ZVolpNo0q5hkl1G0PY+l8eU:U+2BgnjcaxJ1+bMwRUgskl5Q+l8eIg
|
扫描器版本 | 1.0.189.174 |
数据库版本 | 2024-09-19 20:00:25 UTC |
被 7 个安全引擎检测到 - 需要谨慎
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
60a8d7d614559af8251d35bd8ede42c4
|
|
SHA1 |
8312b2c74891967950cae633edb6880960bc6179
|
|
SHA256 |
cc4b03d0be02aa5a5f853f6ec627b7b2d20f8d34696f495198ab19e0835444ab
|
|
SHA512 |
c8261161f182c310e88b6aa1b7522bad5b38c1c2223a6572978abb96357d5905c432754c5d9334aa42b5340acb7d170e538315e39493201da1b389be94b60de1
|
|
ImpHash |
d42595b695fc008ef2c56aabd8efd68e
|
映像基址 | 0x00400000 |
入口点 | 0x0046f380 |
编译时间 | 1970-01-01 00:00:00 |
校验和 | 0x00000000 (实际: 0x0024a488) |
操作系统版本 | 6.1 |
PEiD 签名 |
PE32+ executable (console) x86-64, for MS Windows
|
数字签名 | The PE file does not contain a certificate table. |
导入 |
1 库
kernel32 |
导出 | 0 函数 |
资源 | 0 资源 |
节 | 15 节 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
663,787 bytes | 664,064 bytes | 6.23 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
631E777F0CFB44F330E44129472F544F |
.rdata |
0x000a4000 |
820,552 bytes | 820,736 bytes | 5.40 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A4F404265657D530B28F0414C0F60F1E |
.data |
0x0016d000 |
347,936 bytes | 49,664 bytes | 2.74 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
888020E13246CB954809246842AEE38A |
.pdata |
0x001c2000 |
19,452 bytes | 19,456 bytes | 5.18 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B4C760610832BD94C744935A727DA6B5 |
.xdata |
0x001c7000 |
180 bytes | 512 bytes | 1.79 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
FAC25B195F6AC54CA1AD3E65E5409B1C |
/4 |
0x001c8000 |
332 bytes | 512 bytes | 5.61 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
AAF28638A5FCA2AE9B61C2D0ECB5C6E7 |
/19 |
0x001c9000 |
151,871 bytes | 152,064 bytes | 7.99 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
2F34D32FB0CB502660F36D47DD5BC870 |
/32 |
0x001ef000 |
30,706 bytes | 30,720 bytes | 7.92 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
68EB9C31941EFA4CA1B178B7E63FD602 |
/46 |
0x001f7000 |
48 bytes | 512 bytes | 0.86 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
40CCA7C46FC713B4F088E5D440CA7931 |
/65 |
0x001f8000 |
288,015 bytes | 288,256 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
82A20F54F4242A2CC3B010E248423B77 |
/78 |
0x0023f000 |
151,276 bytes | 151,552 bytes | 7.99 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
5B59BEA151D585640F39EE31F98C2F91 |
/90 |
0x00264000 |
54,923 bytes | 55,296 bytes | 7.79 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES
|
48FEA1AABD6D712105A658CA92704193 |
.idata |
0x00272000 |
1,342 bytes | 1,536 bytes | 4.02 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
5448D5E07103AEDF7D79B8339365D5A0 |
.reloc |
0x00273000 |
14,208 bytes | 14,336 bytes | 5.42 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
77B44332287142D7CD0391092D682939 |
.symtab |
0x00277000 |
106,749 bytes | 107,008 bytes | 5.04 (正常) |
IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
2DC877A144D1A1BBF53CB8C987EADB07 |
5 检测到高熵(≥7.5)的节 - 可能存在打包/加密
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
The PE file does not contain a certificate table.
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要