builder.exe

First submission 2024-10-14 19:23:02 Last sumbission 2024-10-14 19:24:02

File details

File type: PE32 executable (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 469.5 KB (480768 bytes)
Compile time: 2022-09-14 01:31:18
MD5: c2bc344f6dde0573ea9acdfb6698bf4c
SHA1: d6ae7dc2462c8c35c4a074b0a62f07cfef873c77
SHA256: a736269f5f3a9f2e11dd776e352e1801bc28bb699e47876784b8ef761e0062db
Import Hash : d2e26e45dcb84f1062f90f29a9cf0faa
Sections 4 .text .rdata .data .rsrc
Directories 3 import resource debug

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 67/77 VT report date: 2024-10-14 03:59:21
Malware Type 2 trojan ransomware
Threat Type 3 lockbit blackmatter udochka

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXps://raw.githubusercontent.com/tennessene/lockbit/refs/heads/main/builder.exe VirusTotal Report raw.githubusercontent.com VirusTotal Report 2024-10-14 19:23:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x4f62 20480 efd46f03325151f6408c386c8d18a90a8b52a317 79c40b72f11f7c27a613280e6ee38de7
.rdata 0x6000 0x650 2048 36278a04e0cd8b0027b32e31794c946a2977ba83 f9403f872fa05912a4398acb57df8253
.data 0x7000 0x1f73 8192 6595fcedd32cf10e5a066365efbf21e78b76cdb7 5fafb72782f62f71b9b4f605c0d0f200
.rsrc 0x9000 0x6d8f0 449024 b752614c54b1f05ddd70ed41e6e5005730737477 e0412095edacaa6868ff93226044a968

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_RCDATA LANG_ENGLISH SUBLANG_ENGLISH_US 0x5e4f0 99328

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Log
trial_dec.log
Data
ntuser.dat
Text
%s.README.txt
Password_dll.txt
Password_exe.txt
Library
ADVAPI32.dll
ntdll.dll
SHLWAPI.dll
SHELL32.dll
encryptor3dll.dll
WTSAPI32.dll
COMCTL32.dll
USER32.dll
MSVCRT.dll
GDI32.dll
imagehlp.dll
MPR.dll
KERNEL32.dll

Strings analysis - Possible URLs found 2

http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://www.ibsensoftware.com/

Import functions