Nombre del Archivo | svchost.exe |
Tipo de Archivo |
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
|
Versión del Escáner | 1.0.172.174 |
Versión de la Base de Datos | 2024-04-18 18:00:28 UTC |
Familia de malware: Packed
Tipo de Hash | Valor | Acción |
---|---|---|
MD5 |
255850326fc8149ad7e635403c2de2bf
|
|
SHA1 |
0a4e6c76b7dab7ba445c1c0644c66f8579876200
|
|
SHA256 |
a761634b9327e17ea3330bb3ea6977f4d95e3c972f46d972a90b33d49739f5c4
|
|
SHA512 |
15e262bb018e56e0d65f1271263e612a85783d7f820d29379f5c1bdede59aacd76a119de61220be500ac60319b7f45abaaae917970aad86f1a0784b2df91ecec
|
|
ImpHash |
4d8a465943edbfae7c3166b9af900360
|
Icono |
Hash: f976ca290892cdb98cba4f6b0ff69089
Difuso: be3977b5a702e9c4f9fcc82194460771 dHash: 2c9cb83cbcd8f472 |
Base de Imagen | 0x140000000 |
Punto de Entrada | 0x144b63144 |
Tiempo de Compilación | 2023-06-25 21:41:03 |
Suma de Verificación | 0x03d5ef3d (Real: 0x02671212) |
Versión del SO | 4.0 |
Firmas PEiD |
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
|
Firma Digital | The PE file does not contain a certificate table. |
Importaciones | 13 bibliotecas |
Exportaciones | 41 funciones |
Recursos | 5 Recursos |
Secciones | 16 Secciones |
CompanyName | D0kt0r Solutions |
FileDescription | SRBMiner-MULTI |
FileVersion | 2.3.0 |
LegalCopyright | 2023 D0kt0r |
ProductName | SRBMiner-MULTI |
ProductVersion | 2.3.0 |
Translation | 0x0000 0x04b0 |
Nombre | Dirección Virtual | Tamaño Virtual | Tamaño Bruto | Entropía | Características | MD5 |
---|---|---|---|---|---|---|
|
0x00001000 |
13,209,600 bytes | 3,462,656 bytes | 8.00 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D2A21419993C8453DCD61505A49E4A7D |
|
0x00c9a000 |
45,056 bytes | 4,096 bytes | 7.60 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
32C74BC41B6BD9D484D771EF0342CE46 |
|
0x00ca5000 |
48,615,424 bytes | 31,250,432 bytes | 8.00 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
4515BFC5430B04DF463065C6E7F757AD |
|
0x03b02000 |
1,691,648 bytes | 493,056 bytes | 8.00 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6ABA2902EC2BFE5139946009389636D0 |
|
0x03c9f000 |
159,744 bytes | 97,280 bytes | 8.00 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
14D32C690BEEABD2460208D849701F70 |
|
0x03cc6000 |
561,152 bytes | 126,976 bytes | 8.00 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
91F02DB02DE36BD447CCB3C38858A1B2 |
|
0x03d4f000 |
81,920 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_64BYTES
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d63000 |
4,096 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d64000 |
24,576 bytes | 512 bytes | 3.01 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
ECD01ACF1F6931E81CBEC79DB5D22EC8 |
|
0x03d6a000 |
4,096 bytes | 512 bytes | 0.76 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
087E0BF61EDF0720F5812AFDC3B0F7FF |
|
0x03d6b000 |
4,096 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d6c000 |
8,192 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x03d6e000 |
20,480 bytes | 5,632 bytes | 7.67 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
192475E5B80632748E02354745D9AE58 |
.rsrc |
0x03d73000 |
8,192 bytes | 6,144 bytes | 4.43 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
DEEBDAA8FE2AE069C537D68AE3A194AA |
|
0x03d75000 |
11,677,696 bytes | 1,887,232 bytes | 8.00 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
248DE35446412BEA163FCF0D9465300D |
|
0x04898000 |
2,949,120 bytes | 2,948,608 bytes | 7.96 (Empaquetado/Cifrado) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A802D56649BAB5170A8C861B037E7448 |
9 sección(es) con alta entropía (≥7.5) detectada(s) - posible empaquetado/cifrado
Tipo de Recurso | Cantidad | Tamaño Total | Porcentaje |
---|---|---|---|
RT_ICON | 2 | 3,600 bytes | |
RT_GROUP_ICON | 1 | 34 bytes | |
RT_VERSION | 1 | 576 bytes | |
RT_MANIFEST | 1 | 1,167 bytes |
Este archivo no está firmado digitalmente.
⚠ Este archivo carece de firma digital o la cadena de certificados no pudo ser verificada.
Tenga precaución al ejecutar archivos sin firmar de fuentes desconocidas.
The PE file does not contain a certificate table.
Recomendación: Verifique la fuente del archivo y asegúrese de que provenga de un editor confiable.
Gridinsoft tiene la capacidad de identificar y eliminar Trojan.Win64.Packed.cl sin requerir intervención adicional del usuario.
Descargar Anti-MalwareSiga estos pasos para eliminar completamente la amenaza de su sistema
Cure su PC de cualquier tipo de malware
GridinSoft Anti-Malware lo ayudará a proteger su computadora contra spyware, troyanos, puertas traseras, rootkits. Limpia su sistema de molestos módulos publicitarios y otras cosas maliciosas desarrolladas por piratas informáticos.