File Name | uploaded_file |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.138.174 |
Database Version | 2023-09-10 23:01:43 UTC |
Malware family: Dharma
Hash Type | Value | Action |
---|---|---|
MD5 |
acdef64bfc298f59ed5033ff3b8b7e36
|
|
SHA1 |
4db6303b746a796f216f7166f19a05a63e1d654d
|
|
SHA256 |
f0293711a8c78a638c60cd57874b3b5db52701b7b5e3ff32f309d1f2160c48b9
|
|
SHA512 |
6b12939ab6aa92fcee3b9523aa6bea58bce5dadf5fed94e294fd3e8539cc44860f0be0c86acca15343624367ef71bc1e3c8d7624db2328cd249b796db2fada32
|
|
ImpHash |
f86dec4a80961955a89e7ed62046cc0e
|
Image Base | 0x00400000 |
Entry Point | 0x0040a9d0 |
Compilation Time | 2017-03-02 23:49:06 |
Checksum | 0x00000000 (Actual: 0x000209c3) |
OS Version | 5.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | C:\crysis\Release\PDB\payload.pdb |
Digital Signature | The PE file does not contain a certificate table. |
Imports |
1 libraries
KERNEL32 |
Exports | 0 functions |
Resources | 0 Resources |
Sections | 3 Sections |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
39,973 bytes | 40,448 bytes | 5.97 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
FBDFBBCD720021A23C9E78B5511496B0 |
.rdata |
0x0000b000 |
9,782 bytes | 10,240 bytes | 7.79 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
BBEAE82A2350EEB7334FA155EBEC76D2 |
.data |
0x0000e000 |
43,733 bytes | 43,008 bytes | 7.98 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
963541C7DD2D499357D594EB9BE77761 |
2 section(s) with high entropy (≥7.5) detected - possible packing/encryption
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
The PE file does not contain a certificate table.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Ransom.Win32.Dharma.bot without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system