Nom du fichier | SAntivirusWD.exe |
Type de fichier |
PE32+ executable (console) x86-64, for MS Windows
|
Version du scanner | 1.0.154.174 |
Version de la base de données | 2024-01-15 01:03:51 UTC |
Famille de malware: Heuristic
Type de hachage | Valeur | Action |
---|---|---|
MD5 |
f0d41c048482ae563bfaba92f4b323df
|
|
SHA1 |
f7db99926c1c4408921365f9dfda9e23ada2a783
|
|
SHA256 |
5013e953a55534b83f74be41d5a08048f57e52be78c776566d58d296a0e7b381
|
|
SHA512 |
ac180878080123baf5e99b0419b3a9f7ad6c7e2bbd8a82e6b45dd94d3de48e2fc17545221aec94fbe421371ae8f1cc2b331615d279cf26e1d71508d5640a014d
|
|
ImpHash |
87b79871203ea245059d92a2ab553b6f
|
IcĂŽne |
Hachage: f33c31bbe5e37d7d2d48f3b2f9dbf889
Flou: 14e33edbae4e2016dd5ba8d1dc15dddc dHash: c08362434b69a6c8 |
Base d'image | 0x140000000 |
Point d'entrée | 0x1400ec474 |
Heure de compilation | 2023-04-07 18:11:07 |
Somme de contrÎle | 0x0074ef7b (Réel: 0x04752629) |
Version OS | 6.0 |
Signatures PEiD |
PE32+ executable (console) x86-64, for MS Windows
|
Signature numérique | Unknown certificate revision b5e6 |
Importations | 19 bibliothĂšques |
Exportations | 0 fonctions |
Ressources | 7 Ressources |
Sections | 16 Sections |
Segurazo Security | Segurazo Security (CA) |
CompanyName | DlGlTAL COMMUNICATIONS INC |
FileDescription | IServ |
FileVersion | 1.0.22.33 |
InternalName | IServ |
LegalCopyright | DlGlTAL COMMUNICATIONS INC |
OriginalFilename | IServ |
ProductName | IServ |
ProductVersion | 1.0.22.33 |
Translation | 0x0409 0x04b0 |
Nom | Adresse virtuelle | Taille virtuelle | Taille brute | Entropie | Caractéristiques | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
2,314,080 bytes | 2,314,240 bytes | 6.48 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
3B4ED70EABEE589BD2A0155DAE93E2CE |
.fdata |
0x00236000 |
186 bytes | 512 bytes | 2.77 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
ED044A3C2E2DC7EF655EE144D336FCAB |
.code2 |
0x00237000 |
479 bytes | 512 bytes | 4.34 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
C2262431B34FEC58E005756A1BAC3D27 |
.code3 |
0x00238000 |
3,928 bytes | 4,096 bytes | 5.97 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
41B1B7CAC9BF4A0ECF098B8E536893F2 |
.code4 |
0x00239000 |
1,196 bytes | 1,536 bytes | 5.35 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8FE73101A44FB0C26480D0DFAAD53170 |
.code1 |
0x0023a000 |
2,412 bytes | 2,560 bytes | 5.97 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
276368249272FC22F2B7B739FDDAC430 |
.code |
0x0023b000 |
11,752 bytes | 11,776 bytes | 6.01 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E30C336F54417A0B1936CD86FA6373BB |
.code5 |
0x0023e000 |
1,190 bytes | 1,536 bytes | 4.91 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E7E161C8CE6598336FF4B62A64108C1D |
.code6 |
0x0023f000 |
9,544 bytes | 9,728 bytes | 5.85 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
2372CAE56E81CCBECF220BCD028B5844 |
.code7 |
0x00242000 |
9,692 bytes | 9,728 bytes | 6.09 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
758FE1DEF761BAB35FF309FDD7857C54 |
.rdata |
0x00245000 |
4,849,178 bytes | 4,849,664 bytes | 7.89 (Compressé/Chiffré) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
2EA14844A082BF6087880025AF54FD5E |
.data |
0x006e5000 |
79,180 bytes | 64,000 bytes | 5.23 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
887F958AAA144E44F2B18E3A3C40A8B6 |
.pdata |
0x006f9000 |
118,644 bytes | 118,784 bytes | 6.32 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E3914A36A6DA74AFE36A32153EFF98C7 |
.gfids |
0x00716000 |
5,652 bytes | 6,144 bytes | 3.84 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
7531A774DA6AEA899F517B19172BD653 |
.tls |
0x00718000 |
9 bytes | 512 bytes | 0.02 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1F354D76203061BFDD5A53DAE48D5435 |
.rsrc |
0x00719000 |
257,160 bytes | 257,536 bytes | 7.96 (Compressé/Chiffré) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
2E036F7CC01D1B7C084DF8E5EB3F657F |
2 section(s) avec entropie Ă©levĂ©e (â„7.5) dĂ©tectĂ©e(s) - compression/chiffrement possible
Type de ressource | Nombre | Taille totale | Pourcentage |
---|---|---|---|
RT_ICON | 2 | 13,904 octets | |
RT_RCDATA | 2 | 241,648 octets | |
RT_GROUP_ICON | 1 | 34 octets | |
RT_VERSION | 1 | 700 octets | |
RT_MANIFEST | 1 | 381 octets |
Sujet |
Segurazo Security Segurazo Security CA |
Ămetteur | Segurazo Security |
Numéro de série | -2777590441930211166224332569712903199 |
Unknown certificate revision b5e6
Recommandation: Vérifiez la source du fichier et assurez-vous qu'il provient d'un éditeur de confiance.
Gridinsoft est capable d'identifier et de supprimer Trojan.Heur!.00016023 sans nécessiter l'intervention de l'utilisateur.
Télécharger Anti-MalwareSuivez ces étapes pour supprimer complÚtement la menace de votre systÚme
Débarrassez votre PC de tout type de malwares
GridinSoft Anti-Malware vous aidera à protéger votre ordinateur contre les logiciels espions, les chevaux de Troie, les portes dérobées, les rootkits. Il nettoie votre systÚme des modules publicitaires agaçants et d'autres éléments malveillants développés par des pirates.