文件名 | Nuevo pedido (1M85700).exe |
文件类型 |
Win32 EXE
|
魔术字节 | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
SSDEEP 哈希 |
24576:Q3HYcxXrV+rB4vjXqqH3y7wwopt5/i6noItfef9q+qF6YaDWt6n:Q3TtIB4WqHC7wwopt9i6oUAq+qFSWt6n
|
扫描器版本 | 1.0.211.174 |
数据库版本 | 2025-03-24 23:01:10 UTC |
被 10 个安全引擎检测到 - 需要谨慎
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
666231157a1aa72b467c82c7aba16653
|
|
SHA1 |
1fed551514389221dd64979a4f705804d0d6f660
|
|
SHA256 |
dde6b5b337fbb0c75ba9198962dedc4eb0a1c0d33372096033e995379aca7e60
|
|
SHA512 |
7574475068136867f7341723cd7de3d6436ad3d3c30a486d5e6305712a944d31a67db596cd3347e7a03cc9b6b4d31f49e6f34579c4fe7fb8f3f8934482eb31b2
|
|
ImpHash |
6e7f9a29f2c85394521a08b9f31f6275
|
图标 |
哈希: 310d854139d6fe74c65164a466bd1868
模糊: 9101b376392060382757729bdb5b7c09 dHash: 2939dc1cdcccfc7c |
映像基址 | 0x00400000 |
入口点 | 0x004034a2 |
编译时间 | 2020-08-01 02:41:11 |
校验和 | 0x00119a2c (实际: 0x00119a2c) |
操作系统版本 | 4.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
数字签名 | Chain verification from CN=Unprovidedly, [email protected], O=Unprovidedly, L=Montjean-sur-Loire, ST=Pays de la Loire, C=FR (serial:678703297495775971713106741614318929653135395691, sha1:64de851f3d53b8b129d9c67feeaf1c3eca066338) failed: The X.509 certificate provided is self-signed - "Common Name: Unprovidedly, Email Address: [email protected], Organization: Unprovidedly, Locality: Montjean-sur-Loire, State/Province: Pays de la Loire, Country: FR" |
导入 |
7 库
ADVAPI32, SHELL32, ole32, COMCTL32, USER32, GDI32, KERNEL32 |
导出 | 0 函数 |
资源 | 15 资源 |
节 | 5 节 |
Comments | Federal Express Corp. |
FileDescription | Jones Apparel Group Inc. |
LegalTrademarks | ACT Manufacturing Inc. |
OriginalFilename | tsarrigets.exe |
ProductName | Greif Bros. Corporation |
Translation | 0x0409 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
25,964 bytes | 26,112 bytes | 6.47 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
12117AD2476C7A7912407AF0DCFCB8A7 |
.rdata |
0x00008000 |
5,016 bytes | 5,120 bytes | 5.14 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E3E8D62E1D2308B175349EB9DAA266C8 |
.data |
0x0000a000 |
3,795,832 bytes | 1,536 bytes | 4.02 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
2020CA26E010546720FD467C5D087B57 |
.ndata |
0x003a9000 |
167,936 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x003d2000 |
29,752 bytes | 30,208 bytes | 3.79 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A9810D2A4A50E720BA796A4F629DB203 |
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 8 | 26,560 字节 | |
RT_DIALOG | 4 | 760 字节 | |
RT_GROUP_ICON | 1 | 118 字节 | |
RT_VERSION | 1 | 620 字节 | |
RT_MANIFEST | 1 | 832 字节 |
产品 | Greif Bros. Corporation |
描述 | Jones Apparel Group Inc. |
原始名称 | tsarrigets.exe |
验证状态 | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. |
签名者 | Unprovidedly |
76 E2 1B C2 3A 13 57 3D 75 ED 49 43 79 31 0E B2 DC 71 4B 6B
✓ 此文件已进行数字签名,证书链已验证。
Chain verification from CN=Unprovidedly, [email protected], O=Unprovidedly, L=Montjean-sur-Loire, ST=Pays de la Loire, C=FR (serial:678703297495775971713106741614318929653135395691, sha1:64de851f3d53b8b129d9c67feeaf1c3eca066338) failed: The X.509 certificate provided is self-signed - "Common Name: Unprovidedly, Email Address: [email protected], Organization: Unprovidedly, Locality: Montjean-sur-Loire, State/Province: Pays de la Loire, Country: FR"
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要