在线病毒检测器 | v.1.0.190.174 |
数据库版本: | 2024-09-22 20:00:26 |
RedLine Stealer是一种恶意程序,旨在从浏览器、系统和已安装软件中窃取用户的机密数据。它通常通过电子邮件附件或被攻陷的网站传递。RedLine不仅窃取敏感信息,还通过引入其他恶意软件到受害者的操作系统中构成重大威胁。这种双重攻击方式使RedLine成为一个强大而危险的网络威胁。
File | modest-menu.exe |
已检查 | 2024-09-22 17:29:20 |
MD5 | 95b19538dfa7a5a409124b7a415e4764 |
SHA1 | cbabc2829faf533b99191bde1e12612a1d23509b |
SHA256 | cd07f55fee9c352d07424a5a45e657f139d908bdfa73896f6dc92402dd42a6ca |
SHA512 | 0465df7bdf21cac1be4fb916d44099ed4f4a6aa20108595fee2333b5431eeeb623a99654315db6f53922098bbfac7793fa6455d7c17167e389466b5b8fb5cb50 |
Imphash | 4328f7206db519cd4e82283211d98e83 |
File Size | 4956972 bytes |
Gridinsoft能够识别并消除Trojan.Win32.RedLine.mz!n,无需进一步的用户干预。
Translation | 0x0000 0x04b0 |
Comments | XHP Booster |
CompanyName | |
FileDescription | XHP |
FileVersion | 12.9.1.22 |
InternalName | Seignories.exe |
LegalCopyright | XHP Corporation Copyright © 2021 |
LegalTrademarks | |
OriginalFilename | Seignories.exe |
ProductName | XHP booster |
ProductVersion | 12.9.1.22 |
Assembly Version | 1.1.21.1 |
fd0d7e7755adc0ea9ccca581d1f3389e b268c68a90cd683448e21cd46852730e 00ccd8d4ccf030c4 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00f16000 |
Compilation: | 2077-08-19 09:06:07 |
Checksum: | 0x004bb212 (Actual: 0x004c7457) |
OS Version: | 4.0 |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | The expected hash does not match the digest in SpcInfo |
Sections: | 8 |
Imports: | kernel32, mscoree, |
Exports: | 0 |
Resources: | 5 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00002000 | 0x00030000 | 0x0002ec00 | 89ce047eac735b996fb8e73869e637c2 | 6.21 |
0x00032000 | 0x0002420c | 0x0000f005 | 02193c69c72b975d3d4259730143fb82 | 7.95 | |
0x00058000 | 0x0000000c | 0x0000000f | 7bab651e9acd8b6d5eb282045d93c64f | 3.77 | |
.imports | 0x0005a000 | 0x00002000 | 0x00000400 | 7f8970a849f0d15e9a35fd0a70ee89cb | 0.64 |
.rsrc | 0x0005c000 | 0x0000c400 | 0x0000c400 | bc59ef6101e36c544f6964e3bf9844ce | 7.90 |
.themida | 0x0006a000 | 0x00640000 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.boot | 0x006aa000 | 0x0046a400 | 0x0046a400 | 794ea5fd501e21c8292ac9ee65112da4 | 7.95 |
.taggant | 0x00b16000 | 0x00002400 | 0x00002014 | bb61bbabc38922589d1762a03b6014ed | 0.30 |