390cd31ac20cdeff0127d074aff0728157fbc5ef1f93e8ba98042bf22c1c6fc6

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jun-26 04:28:48
Debug artifacts D:\a\_work\1\s\src\runtime\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName Ixar
FileDescription ransom
FileVersion 1.0.0.0
InternalName ransom.dll
LegalCopyright
OriginalFilename ransom.dll
ProductName ransom
ProductVersion 1.0.0
Assembly Version 1.0.0.0

Plugin Output

Suspicious PEiD Signature: MoleBox v2.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • adobe.com
  • github.com
  • http://ns.adobe.com
  • http://ns.adobe.com/exif/1.0/aux/
  • http://ns.adobe.com/photoshop/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://purl.org
  • http://www.iec.ch
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • https://aka.ms
  • https://github.com
  • ns.adobe.com
  • www.iec.ch
  • www.w3.org
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExW
  • RegGetValueW
Possibly launches other programs:
  • ShellExecuteW
Suspicious The file contains overlay data. 23320539 bytes of data starting at offset 0x50200.
The overlay data has an entropy of 7.15179 and is possibly compressed or encrypted.
Overlay data amounts for 98.6122% of the executable.
Suspicious VirusTotal score: 2/70 (Scanned on 2026-09-06 13:18:49) APEX: Malicious
Malwarebytes: Ransom.FileCryptor

Hashes

MD5 dc66db69f33c9c92ba0e88cfe59aaf9d 🔍
SHA1 e9c2d7ff294bfd61e31e9b272151a5f1805e29d0 🔍
SHA256 390cd31ac20cdeff0127d074aff0728157fbc5ef1f93e8ba98042bf22c1c6fc6 🔍
SHA3 7a1569c05e6f666ae21d083d19a8d43b314394a4eca4a933ac75e03e62b92a8c 🔍
SSDeep 393216:3tDs78STyOyxE1XstMHsuKdD657mLzV0ty0bTr47d6aGbsDoXq/TUE6t+ajxOOEn:3iISTy3uXshJWcoZ0causDoXqYE6oajq 🔍
Imports Hash 53e4e12437621212a425d294842d0a96 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jun-26 04:28:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x18400
SizeOfInitializedData 0x38a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000013BA0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x55000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e339f76efadd4ce34819f7605f952957 🔍
SHA1 d8c0408818589e37962d999ec6af7d260d898b1f 🔍
SHA256 0268b1011057c783acb003a54d61af8f3db469a2d1b161a52c939ed4a38b3c37 🔍
SHA3 f31a5c6c26b1db46ba1d7db704cba1ea1369e764c5b0c26a91b3aa76abc9d548 🔍
VirtualSize 0x183bc
VirtualAddress 0x1000
SizeOfRawData 0x18400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36586

.rdata

MD5 ac02bae2a4c2863f242f89894f1ceb11 🔍
SHA1 ed8c628e7b2359c1272bb384a26e9a227dfa4841 🔍
SHA256 a52d2655049634a455852007f76e07955ebdc89f83bac0d13b6b4e19f77303e3 🔍
SHA3 c5c1fbb544b05fdd1c93f27acb794917a0ec574d4f643ca2210ed2c60aada5fc 🔍
VirtualSize 0xc5fe
VirtualAddress 0x1a000
SizeOfRawData 0xc600
PointerToRawData 0x18800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.84858

.data

MD5 72871b3fe335ad30637bafabf722395f 🔍
SHA1 02bdea8ff996c4ddfe2966f9beadfcdcfa354589 🔍
SHA256 592f847c705efe2fa1243451f80b0fd98922836b8f6cffecf8af813dff5e7982 🔍
SHA3 24dd4e4c8c188f1fb36482654b859b8153c1a1d46267feef7a79c0c11f9dab69 🔍
VirtualSize 0x1a40
VirtualAddress 0x27000
SizeOfRawData 0xc00
PointerToRawData 0x24e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.22987

.pdata

MD5 24165f8dfccb28f7da4cf026f3968201 🔍
SHA1 4c13384f8be4365f23e7cf1c8572599e9d2e2fcf 🔍
SHA256 46ccf92b7ee0d9686b75fda66946fcb333a0db8a3537cdfa6b4a06f2d5c931aa 🔍
SHA3 3b6e5f48f316f873f1ba655459440c348f39549325278e1772984e38c9279573 🔍
VirtualSize 0x14c4
VirtualAddress 0x29000
SizeOfRawData 0x1600
PointerToRawData 0x25a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.9072

.reloc

MD5 b8472d51988d5beb6dd6b7775bd86a3d 🔍
SHA1 fcb4f44e00d0c78d8c02e26cb1ef31d844b28625 🔍
SHA256 1c65c020d394bac1d3c25e86dffa7c7e5ad69170ee0b21134f827ee507c43afc 🔍
SHA3 7afe2b2194e8554434f83ea26af9aad4e2aedf047862193dd360b946496157a9 🔍
VirtualSize 0x33c
VirtualAddress 0x2b000
SizeOfRawData 0x400
PointerToRawData 0x27000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.80636

.rsrc

MD5 11358e428a0fef8df2e92fd67f433ece 🔍
SHA1 0ed6839b49a187ed3597f5f6c09b360701d7421b 🔍
SHA256 61037dc5dbd431e8563d0bcf9be893926b902693ce822e16140251bf3c8f277a 🔍
SHA3 cc799bed654431c79b3c94c2694bbc23e60c4454b9a5f63b23e8f359d0b74277 🔍
VirtualSize 0x28ce0
VirtualAddress 0x2c000
SizeOfRawData 0x28e00
PointerToRawData 0x27400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.03837

Imports

SHELL32.dll ShellExecuteW
ADVAPI32.dll RegCloseKey
ReportEventW
RegisterEventSourceW
RegOpenKeyExW
RegGetValueW
DeregisterEventSource
KERNEL32.dll TlsFree
CreateActCtxW
ActivateActCtx
GetLastError
FindResourceW
GetWindowsDirectoryW
GetProcAddress
GetModuleHandleW
FreeLibrary
LoadLibraryExW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetStdHandle
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
GetEnvironmentVariableW
FindClose
GetFileAttributesW
MultiByteToWideChar
GetConsoleMode
GetFileAttributesExW
LoadLibraryA
WriteConsoleW
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
OutputDebugStringW
GetCurrentProcessId
TlsSetValue
TlsGetValue
TlsAlloc
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetStringTypeW
SwitchToThread
GetCurrentThreadId
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
USER32.dll MessageBoxW
api-ms-win-crt-runtime-l1-1-0.dll terminate
_register_thread_local_exe_atexit_callback
_c_exit
__p___wargv
__p___argc
_exit
exit
_initterm_e
_errno
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_crt_atexit
_register_onexit_function
_initialize_onexit_table
abort
_invoke_watson
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
malloc
_callnewh
free
api-ms-win-crt-time-l1-1-0.dll _time64
_gmtime64_s
wcsftime
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vfwprintf
__p__commode
fputwc
__acrt_iob_func
__stdio_common_vswprintf
_set_fmode
_wfsopen
fflush
setvbuf
__stdio_common_vsnwprintf_s
api-ms-win-crt-locale-l1-1-0.dll _create_locale
___mb_cur_max_func
___lc_codepage_func
___lc_locale_name_func
__pctype_func
_configthreadlocale
setlocale
_lock_locales
_free_locale
_unlock_locales
api-ms-win-crt-string-l1-1-0.dll strlen
strcmp
wcsncmp
toupper
strcpy_s
_wcsdup
wcsnlen
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstoul
api-ms-win-crt-math-l1-1-0.dll __setusermatherr

Delayed Imports

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x28708
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.970607
MD5 1914b3ca64d694401265d44c59f803ad 🔍
SHA1 485665c6c0bd8a5a7d73e4375fba651bdc555648 🔍
SHA256 8b559282c239b74ddff4064d7ed6384e02693eba68b2f938e8b2ecfedc11ccac 🔍
SHA3 0e253752807f95e5eeb70f6acebd0243314100b1c895bb3f9cc713f2e0b58946 🔍

32512

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 8843e66f24cc9df5b97712f9231fd0db 🔍
SHA1 ac8daed60471710470aac8d79e0f23ba57d7c14c 🔍
SHA256 a27cf103bca72926047a6625fb69704e41e59738ff7b2c91854cacc2f9f4585a 🔍
SHA3 8fecfb6c7f9f9f5630169db0d8f2a40e3e11f83b90efd3fead24290c5a9bac31 🔍

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17891
MD5 9659071d4ca3b26801451a6c5f0988dd 🔍
SHA1 4c3cd6c3e17a2bbb13286a62ff5fbae55e5aa52e 🔍
SHA256 f20c15bbf2003b7b370209315a9cf5c75a1f530d054c9b07e6e4ffbcbe443d63 🔍
SHA3 ffb1232cdc7114e523f2d6806bb164c874ce53ab79b95e69092b43155dd58845 🔍

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9 🔍
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734 🔍
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a 🔍
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Ixar
FileDescription ransom
FileVersion (#2) 1.0.0.0
InternalName ransom.dll
LegalCopyright
OriginalFilename ransom.dll
ProductName ransom
ProductVersion (#2) 1.0.0
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Jun-26 19:39:09
Version 0.0
SizeofData 121
AddressOfRawData 0x22e2c
PointerToRawData 0x2162c
Referenced File D:\a\_work\1\s\src\runtime\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Jun-26 19:39:09
Version 0.0
SizeofData 20
AddressOfRawData 0x22ea8
PointerToRawData 0x216a8

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jun-26 19:39:09
Version 0.0
SizeofData 988
AddressOfRawData 0x22ebc
PointerToRawData 0x216bc

UNKNOWN

Characteristics 0
TimeDateStamp 2026-Jun-26 19:39:09
Version 0.0
SizeofData 4
AddressOfRawData 0x232c0
PointerToRawData 0x21ac0

TLS Callbacks

StartAddressOfRawData 0x1400232e8
EndAddressOfRawData 0x1400232f8
AddressOfIndex 0x140028a28
AddressOfCallbacks 0x14001a518
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x1400270c0
GuardCFCheckFunctionPointer 5368816712
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x2c9dd37e
Unmarked objects 0
ASM objects (35207) 10
C objects (35207) 13
C++ objects (35207) 86
Imports (VS2008 SP1 build 30729) 16
Imports (33145) 9
Total imports 212
C++ objects (LTCG) (35223) 10
Linker (35223) 1

Errors

Leave a comment

No comments yet.