File Name | StaffBesting.dll |
File Type |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
Scanner Version | 1.0.161.174 |
Database Version | 2024-02-14 00:00:14 UTC |
Malware family: AI
Hash Type | Value | Action |
---|---|---|
MD5 |
a14753fb998eded71e6ab962ef0273dd
|
|
SHA1 |
81f9d20a7a1d24bc1eda05c905a9fb821dd2b5f4
|
|
SHA256 |
3090a5f1f6dde4632a8575b43aabef6b288c710a6f24607b79a43e5201018047
|
|
SHA512 |
230450b8b17e28eaf78954cfd15cef937eda215e458620f5bb37c86ea88e014f6e26215009b8ea7dc5262ea7436293f91d380329e6abb91741f4d588645458c6
|
|
ImpHash |
0a2a6780bb9458bac9081365e2bb80f3
|
Image Base | 0x180000000 |
Entry Point | 0x180021994 |
Compilation Time | 2023-04-28 00:00:12 |
Checksum | 0x00039181 (Actual: 0x00039181) |
OS Version | 6.0 |
PEiD Signatures |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
Digital Signature | OK |
Imports | 11 libraries |
Exports | 1 functions |
Resources | 1 Resources |
Sections | 6 Sections |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
136,627 bytes | 136,704 bytes | 6.37 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
0361FFB95BA1D72ED38C2C0852811DC2 |
.rdata |
0x00023000 |
45,996 bytes | 46,080 bytes | 4.18 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E19740E0AD110C9746E07C6CE9821FBC |
.data |
0x0002f000 |
28,832 bytes | 512 bytes | 3.45 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
AAFC8BB28E5959205630DC153DFABA1C |
.pdata |
0x00037000 |
3,708 bytes | 4,096 bytes | 4.86 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A6699DF823ECE240678C1A7A69599B1B |
.rsrc |
0x00038000 |
248 bytes | 512 bytes | 2.53 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0977FE5C8D91EC9B3C527B53DB7B124B |
.reloc |
0x00039000 |
132 bytes | 512 bytes | 1.72 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
FDBE90D3AC384E4E3CF9CCC197150B5D |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_MANIFEST | 1 | 145 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Trojan.Win64.AI.cld without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system