Gridinsoft 在 generator.ryuu.lol 上观察到的情况
Gridinsoft 威胁分析师直接检查了该网站,并记录了支持此决定的证据。
GMA-20260826042233-af1e72e5
- 检查时间
- 由 Gridinsoft 威胁分析师 完成
- 分析师结论
- 可疑网站
- 证据依据
- 第一方网站分析 外部安全厂商情报: 仅作背景参考——未用于本次决定
精确主机仍为可疑网站,因为它公开分发未签名 Windows 工具,并说明高风险的游戏解锁、hooking、注册表、execution policy bypass、token 和激活功能。证据支持 riskware 警示,但不表示新的精确 V2 hash 已确认为 malware、Trojan、stealer 或 phishing。历史有害样本是不同对象。
分析师结论
本次检查记录了 3 项观察
查看证据
精确 V2 Windows 可执行文件仍可公开下载。它是 7,267,328 字节的 PE32+ GUI 文件,具有新的 SHA-256,且没有嵌入 Authenticode 安全目录。旧路径 tool.exe 和 RyuuManifestTool.exe 返回 404;manifest API endpoints 返回 401。
-
HTTP 状态
200 - MIME 类型 application/vnd.microsoft.portable-executable
- 文件 SHA-256 aa53160cbf3eaab665f8d6c1efb8a49ccc194d9e513d8572a115d0bcf7d15e84
- 分析师观察 PE Security Directory address and size were zero; no embedded Authenticode signature was present.
工具页面现已公开说明 Steam hooks 和 loaders、注册表更改、带 execution-policy bypass 的 PowerShell、加密 app-ticket 和 token 辅助组件、激活流程以及其他 EXE 和 DLL 组件。这提高了披露程度,但确认了高风险系统功能。
-
HTTP 状态
200 - 页面元素 The page documents Steam hooks, loaders, registry modification, and PowerShell execution-policy bypass.
- 页面元素 The page documents encrypted app-ticket, token-sharing, and activation components.
公开 sandboxes 包含其他路径和 hashes 的历史文件,包括观察到 stealer 行为的旧 MikeTool.exe。它们不是当前 V2 hash。未找到 SHA-256 aa53160cbf3eaab665f8d6c1efb8a49ccc194d9e513d8572a115d0bcf7d15e84 的公开 sandbox 报告。
- 文件 SHA-256 084dc7059e1e0c6638af3ec20f97222f48a2875193a6f42f37a90daa73791a32
- 分析师观察 The historical malicious sample used a different path and hash from the current V2 executable.
- 分析师观察 No object-level sandbox verdict for the current V2 SHA-256 was located.
范围与限制
- 当前 V2 可执行文件已下载、计算 hash 并静态检查,但 Gridinsoft 未执行它。
- 未执行经过认证的 manifest、token-sharing、激活、Discord、premium 或 game-fix 流程。
- 当前精确 V2 hash 没有公开 sandbox 覆盖;其他路径和 hashes 的历史文件被保持分离。
- 结论适用于 generator.ryuu.lol 及其所审查的运营方控制内容,不适用于 ryuu.lol 上所有无关页面。
帮助保护他人,快在社交媒体上分享此页面吧!知道generator.ryuu.lol的人越多,骗子就越难得逞。 在社交媒体上分享此页面,帮助更多人评估generator.ryuu.lol!