Summary | ZeroBOX
BlackMatter Ransomware PE32 PE File DLL
Category Machine Started Completed
ARCHIVE s1_win7_x6401 Oct. 13, 2023, 1:03 a.m. Oct. 13, 2023, 1:03 a.m.

Archive LBB_Rundll32.dll @ LBB_AEV-iledefrance.fr_05A8F2993F873622_12.08.23_aev_iledefrance.zip

Summary

Size 158.0KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 cf9b606e14c2a720052da5d84e22bd9b
SHA1 074a2f345636364407299593b8f2c4995cf576f0
SHA256 ffa119d06827c2e9f0c078f5a4dea0ad01a98169cb08127cf55984791f8ba916
SHA512
c6c53307cd6e44d2e4f21ad92cace7d6a6103267ee055ce1c7b2a3ec7aef5d7dc2a070a4c4e9a71e6bf873eafe878cd8a0d10ed7da1befff1ae8093441ed7c77
CRC32 2837C48E
ssdeep 3072:D/LecLDzqMDMXSBTWD85cb0EawnJp6V22D86:D/pDzqMGSBTWD85cb0Zwh2D8
Yara
  • BlackMatter_Ransomware_IN - BlackMatter Ransomware
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .itext
section {u'size_of_data': u'0x0000a000', u'virtual_address': u'0x0001b000', u'entropy': 7.983791692214246, u'name': u'.data', u'virtual_size': u'0x0000ad34'} entropy 7.98379169221 description A section with a high entropy has been found
section {u'size_of_data': u'0x00004000', u'virtual_address': u'0x00026000', u'entropy': 7.934046876532605, u'name': u'.pdata', u'virtual_size': u'0x00003e3a'} entropy 7.93404687653 description A section with a high entropy has been found
entropy 0.356687898089 description Overall entropy of this PE file is high