File Name | 护眼宝pc版_2_621911.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-17 13:00:25 UTC |
Malware family: Agent
Hash Type | Value | Action |
---|---|---|
MD5 |
f5417cadf5c6a61c11c003c2bb39462f
|
|
SHA1 |
58be8a8f5e0d44d788598c0e9641c210a2815b04
|
|
SHA256 |
e8012c6840fdb796078f4c13801b7bc432c293320d34876b0bd0174b5713cb18
|
|
SHA512 |
4910ba52ee0816e64395920d6708a56ad01579e98b400ad420bb4758e9184487dc89a36f436757431415d7e1a7ac5a463f9691ea9d2e74300366055e48cb6069
|
|
ImpHash |
9662d8765ed9954d3455fbb14c623fe6
|
Icon |
Hash: 30adcb5c0b2e3c35eaec2c110733c9f8
Fuzzy: c98f96d6ffe5af8d4eb0870c1dc20826 dHash: 92e0b496a6cada72 |
Image Base | 0x00400000 |
Entry Point | 0x0047a333 |
Compilation Time | 2023-06-29 09:08:37 |
Checksum | 0x014276d0 (Actual: 0x014276d0) |
OS Version | 5.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | E:\UIDownloader\bin\Release\setup_1_237148.pdb |
Digital Signature | OK |
Imports | 21 libraries |
Exports | 0 functions |
Resources | 8 Resources |
Sections | 4 Sections |
CompanyName | - |
FileDescription | |
FileVersion | 1.0.7.20 |
LegalCopyright | Copyright (C) 2022 |
OriginalFilename | winManager.exe |
ProductVersion | 1.0.7.20 |
Translation | 0x0804 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
4,248,198 bytes | 4,248,576 bytes | 6.66 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
4C21481B65271DF4A72BF69E4A336590 |
.rdata |
0x0040f000 |
1,017,242 bytes | 1,017,344 bytes | 5.78 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D62146F1EC7AE6A2AB8FED142AA0B0F7 |
.data |
0x00508000 |
15,731,104 bytes | 15,668,736 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9D02BC91772E22940E72F728857DEC97 |
.rsrc |
0x01409000 |
183,248 bytes | 183,296 bytes | 7.98 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E0CC4BB4EFE21A8C8EE2351E24708220 |
2 section(s) with high entropy (≥7.5) detected - possible packing/encryption
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
ZIPRES | 1 | 176,777 bytes | |
RT_ICON | 4 | 4,640 bytes | |
RT_GROUP_ICON | 1 | 62 bytes | |
RT_VERSION | 1 | 556 bytes | |
RT_MANIFEST | 1 | 651 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Trojan.Win32.Agent.cl without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system