文件名 | AltrusicaApp.exe |
文件类型 |
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
扫描器版本 | 1.0.221.174 |
数据库版本 | 2025-07-22 06:00:24 UTC |
恶意软件家族: Altruistik
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
1762eb545be92d5a1cec1e4480f3f8c8
|
|
SHA1 |
768e61ee5fb5ffac9d22a0389c85863a18eecba6
|
|
SHA256 |
e997cd609d51aa72b7e6b9b666f48cd2ab083d0a1005f00ddb042dc140e9c2d4
|
|
SHA512 |
4f2d41a0773fae74573e41d64db1933a4b1aa17ef0c3ed861692a142b5e5ceab526b11b6979c493e9f15bfb2b34f72612275a3c323d95942626b942cb4878d53
|
|
ImpHash |
f34d5f2d4577ed6d9ceec516c1f5a744
|
图标 |
哈希: c1f355bef71cca1ca17f207f65b2fc42
模糊: 71fc48cd59640e82c73a411527e07283 dHash: 33118c0529338e4d |
映像基址 | 0x00400000 |
入口点 | 0x00626e2e |
编译时间 | 2071-02-24 22:06:16 |
校验和 | 0x00243bf5 (实际: 0x00243bf5) |
操作系统版本 | 4.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
数字签名 | Chain verification from CN=FutDevSigner, O=FutDev Solutions LLC, ST=Florida, C=US (serial:-58044954158709656650906580444600821003, sha1:f9539065bc8b06a4b0a96bca7e9b3bc9e09e118b) failed: The X.509 certificate provided is self-signed - "Common Name: FutDevSigner, Organization: FutDev Solutions LLC, State/Province: Florida, Country: US" |
导入 |
1 库
mscoree |
导出 | 0 函数 |
资源 | 4 资源 |
节 | 3 节 |
Translation | 0x0000 0x04b0 |
Comments | Altrusica Application |
CompanyName | |
FileDescription | Altrusica App |
FileVersion | 1.8.0.9 |
InternalName | AltrusicaApp.exe |
LegalCopyright | |
LegalTrademarks | |
OriginalFilename | AltrusicaApp.exe |
ProductName | |
ProductVersion | 1.8.0.9 |
Assembly Version | 1.8.0.9 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00002000 |
2,248,244 bytes | 2,248,704 bytes | 7.60 (打包/加密) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8D774103D0DFEBEC6ECAFA67499E931F |
.rsrc |
0x00228000 |
69,616 bytes | 69,632 bytes | 6.18 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
DA45E6A5FBB903F5F150B1A9D11BB829 |
.reloc |
0x0023a000 |
12 bytes | 512 bytes | 0.10 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
A102CDCBC3224332A2C8DAACD7D7CCD1 |
1 检测到高熵(≥7.5)的节 - 可能存在打包/加密
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 1 | 67,624 字节 | |
RT_GROUP_ICON | 1 | 20 字节 | |
RT_VERSION | 1 | 812 字节 | |
RT_MANIFEST | 1 | 850 字节 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
Chain verification from CN=FutDevSigner, O=FutDev Solutions LLC, ST=Florida, C=US (serial:-58044954158709656650906580444600821003, sha1:f9539065bc8b06a4b0a96bca7e9b3bc9e09e118b) failed: The X.509 certificate provided is self-signed - "Common Name: FutDevSigner, Organization: FutDev Solutions LLC, State/Province: Florida, Country: US"
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁