Author：降草@i春秋

### Murmur hash 算法实现

``````def murmur3_x86_32(data, seed=0):[/size][/align][size=4]    c1 = 0xcc9e2d51
c2 = 0x1b873593
r1 = 15
r2 = 13
m = 5
n = 0xe6546b64

length = len(data)
h1 = seed
rounded_end = (length & 0xfffffffc)  # every block contain 4 bytes
for i in range(0, rounded_end, 4):
# translate to little endian load order
k1 = (ord(data[i]) & 0xff) | ((ord(data[i + 1]) & 0xff) << 8) | \
((ord(data[i + 2]) & 0xff) << 16) | (ord(data[i + 3]) << 24)
k1 *= c1
k1 = (k1 << r1) | ((k1 & 0xffffffff) >> (32-r1))  # ROTL32(k1,15)
k1 *= c2

h1 ^= k1
h1 = (h1 << r2) | ((h1 & 0xffffffff) >> (32-r2))  # ROTL32(h1,13)
h1 = h1 * m + n

# the last block which is < 4 bytes
k1 = 0

val = length & 0x03
# the last block is  3 bytes
if val == 3:
k1 = (ord(data[rounded_end + 2]) & 0xff) << 16
# the last block is  2 bytes
if val in [2, 3]:
k1 |= (ord(data[rounded_end + 1]) & 0xff) << 8
# the last block is  1 bytes
if val in [1, 2, 3]:
k1 |= ord(data[rounded_end]) & 0xff  # translate to little endian load order
k1 *= c1
k1 = (k1 << r1) | ((k1 & 0xffffffff) >> (32-r1))
k1 *= c2
h1 ^= k1

# finalization
h1 ^= length
h1 ^= ((h1 & 0xffffffff) >> 16)
h1 *= 0x85ebca6b
h1 ^= ((h1 & 0xffffffff) >> 13)
h1 *= 0xc2b2ae35
h1 ^= ((h1 & 0xffffffff) >> 16)
# for 32 bit, get the last 32 bits
return h1 & 0xffffffff``````

#### cerber勒索软件中对murmurhash算法的使用

cerber勒索软件对murmurhash函数的使用有两点我们要搞清楚。

1. Murmurhash函数的seed值为什么？
2. 勒索软件调用murmurhash的作用是什么？

1.对于40B074处的算法使用：

3.对于加密文件函数401DB9中的使用 组成下面的数据结构