附加訊息 |
File size: 53760 bytes |
MD5 : 5db09a8e32164e4669f5eadc0cf50182 |
SHA1 : 597d16a19baf7d15a045be41c907b956d1de706b |
SHA256: de08e3d24dc3cafea087936be9b2016951b0b9f5c96399b74c0cc3b2e1c945b6 |
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4DB0
timedatestamp.....: 0x3C9AB6C9 (Fri Mar 22 05:44:57 2002)
machinetype.......: 0x14C (Intel I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x7770 0x7800 6.33 379f1d8b346f49f8a78b9ef41ce4988e
.rdata 0x9000 0x3B7 0x400 4.91 cac6fb464cb39dedce7838704fe783ba
.data 0xA000 0x7264 0x1E00 3.18 af6e0e30aef0fe4c86f58e8ba268514e
.idata 0x12000 0x7EA 0x800 5.26 e6b54897a6●CSOL木馬網站●c514
.rsrc 0x13000 0x1FB0 0x2000 4.27 f9cdac0579eb0b78a7ddc90599d02fc2
.reloc 0x15000 0xB46 0xC00 6.02 d1b257d3d0b7242f65c44383de761431
( 0 imports )
( 0 exports )
|
TrID : File type identification
Win32 Executable MS Visual C++ 4.x (64.8%)
Win32 Executable MS Visual C++ (generic) (18.1%)
Windows Screen Saver (6.3%)
Win32 Executable Generic (4.1%)
Win32 Dynamic Link Library (generic) (3.6%) |
ssdeep: 768:sEqAVbpPSt8JrNlYSwp2pHW7pCJ5aU7UdeJ1bdzRqED5pAD6BDrNg:zP1JpWpQ27pCmU7+eJpdFZl6gxg |
sigcheck: publisher....: Tolunay Orkun
copyright....: Copyright (c) 2002, Tolunay Orkun
product......: Dr. TCP
description..: TCP/IP Tweaking Utility
original name: DRTCP.exe
internal name: DRTCP
file version.: 0.21
comments.....: Written by: Tolunay Orkun
signers......: -
signing date.: -
verified.....: Unsigned
|
PEiD : - |
RDS : NSRL Reference Data Set
-
http://www.virustotal.com/zh-tw/analisis/de08e3d24dc3cafea087936be9b2016951b0b9f5c96399b74c0cc3b2e1c945b6-1277569944
檔案下載地址為:http://fhd.iwgun.net/downfile.php?action=public&file_id=9293&file_key=asSqKNIL
希望幫到大家,如果已經有人上載,我會自行刪除
最後我希望大家回覆,thx~~
|