文件名 | Main.exe |
文件类型 |
PE32+ executable (GUI) x86-64, for MS Windows
|
扫描器版本 | 1.0.215.174 |
数据库版本 | 2025-04-23 13:00:17 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
42469b9c4f846a5dd08c5251333f0d86
|
|
SHA1 |
24eee2037a751ce0741ccb60e3cd8c4a0eea50d1
|
|
SHA256 |
f2cc8860078cfee151fa64846cc7dabf16dc0576420f80870dbdd36fe5e95816
|
|
SHA512 |
5a960df16cc92bfc6325f58febae6b35a78086b8ef36c5f1b693a5e2419facff6863662a1c8de584eae4454bab24eb6e30fb28396884ce34a3411fa26440980f
|
|
ImpHash |
ed86d0ae70e82754ce6f800fb129eb84
|
图标 |
哈希: 616f27f72052b672e89f75c92db08218
模糊: b72e56e5842e66c0f7de5b7e4c7616b2 dHash: c4b2d696ba94a4a2 |
映像基址 | 0x140000000 |
入口点 | 0x1400bcaa0 |
编译时间 | 2025-03-23 22:40:43 |
校验和 | 0x000f78fe (实际: 0x000f78fe) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (GUI) x86-64, for MS Windows
|
PDB 路径 | C:\Users\Ethan\Downloads\InformaalRunner-master (1)\InformaalRunner-master\x64\Release\Main.pdb |
数字签名 | Chain verification from CN=Informaal, O=Informaal LLC, L=Springfield, ST=Illinois, C=United States (serial:41074049011101601784900468512579457902, sha1:7d42056ffa5312f4be7286b63a30500271761afb) failed: The X.509 certificate provided is self-signed - "Common Name: Informaal, Organization: Informaal LLC, Locality: Springfield, State/Province: Illinois, Country: United States" |
导入 | 22 库 |
导出 | 0 函数 |
资源 | 9 资源 |
节 | 6 节 |
FileDescription | Informaal Software |
FileVersion | 1.0.0.1 |
Translation | 0x0409 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
773,244 bytes | 773,632 bytes | 6.54 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
32F4AF9FC6E2580DF2D1301652B17F07 |
.rdata |
0x000be000 |
132,892 bytes | 133,120 bytes | 5.91 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
BBC05A38940ED6D1234FC23779A1B114 |
.data |
0x000df000 |
4,888 bytes | 3,072 bytes | 3.32 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
66E0D73E3F50815028A8706686D82265 |
.pdata |
0x000e1000 |
23,640 bytes | 24,064 bytes | 5.91 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
BAEE8C210564E4B5C5E67A7E181B37EA |
.rsrc |
0x000e7000 |
11,248 bytes | 11,264 bytes | 5.41 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B9A2788548529DFB559A0B97AA5467C7 |
.reloc |
0x000ea000 |
2,164 bytes | 2,560 bytes | 4.99 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
9B5490D2901AAB4BFBE1324E32D86650 |
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
AFX_DIALOG_LAYOUT | 1 | 2 字节 | |
RT_ICON | 4 | 9,552 字节 | |
RT_DIALOG | 1 | 226 字节 | |
RT_GROUP_ICON | 1 | 62 字节 | |
RT_VERSION | 1 | 348 字节 | |
RT_MANIFEST | 1 | 381 字节 |
描述 | Informaal Software |
文件版本 | 1.0.0.1 |
签名日期 | 10:41 PM 03/23/2025 (75 天前) |
验证状态 | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. |
签名者 | Informaal |
1E E6 92 F7 BE 6C 1A 84 45 16 47 B8 64 99 13 6E
0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
✓ 此文件已进行数字签名,证书链已验证。
Chain verification from CN=Informaal, O=Informaal LLC, L=Springfield, ST=Illinois, C=United States (serial:41074049011101601784900468512579457902, sha1:7d42056ffa5312f4be7286b63a30500271761afb) failed: The X.509 certificate provided is self-signed - "Common Name: Informaal, Organization: Informaal LLC, Locality: Springfield, State/Province: Illinois, Country: United States"
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要