🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49e891411c7eb5d49fd52c738dd664879d2b1d6bcb090ce6aeaa0b6342c1ecdc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 12


Intelligence 12 IOCs YARA 2 File information Comments

SHA256 hash: 49e891411c7eb5d49fd52c738dd664879d2b1d6bcb090ce6aeaa0b6342c1ecdc
SHA3-384 hash: 94a023f3442c97a229ff2c7297062e6dddd984ad3cc0eb1b2e976403cc77ee4fe39d7c656934105e50e393a6a05c0b62
SHA1 hash: c68437dc84c22f05ab08ffb1fa56cd752bf51862
MD5 hash: 32cdf76f81e20483f45317febc1ed085
humanhash: king-pasta-uranus-three
File name:SecuriteInfo.com.Trojan.Encoder.37841.18230.3675
Download: download sample
Signature LockBit
File size:250'368 bytes
First seen:2023-12-10 01:19:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2b8bb1a297fc6dbb94dddbb19e3d5648 (1 x LockBit)
ssdeep 3072:1wfFl44aXo6xZKQwwjt5VJZWw0XXttKO27wUkshhY+WHURjiVlmIA2POUR52:1w3nQtjtDDWlXdIwUksRujt1R
Threatray 2 similar samples on MalwareBazaar
TLSH T134343A00B95FDBAAD68303BC4957A602FEF7768027248DE783884A704D0B6D576EDF91
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter SecuriteInfoCom
Tags:exe lockbit

Intelligence


File Origin
# of uploads :
1
# of downloads :
558
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Using the Windows Management Instrumentation requests
Launching a service
Changing a file
Modifying an executable file
Modifies multiple files
Sending a custom TCP request
Reading critical registry keys
Stealing user critical data
Encrypting user's files
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
expand filecoder lockbit lockfile lolbin masquerade
Result
Threat name:
LockBit ransomware
Detection:
malicious
Classification:
rans.spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Found potential ransomware demand text
Found ransom note / readme
Found Tor onion address
Infects executable files (exe, dll, sys, html)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
Writes many files with high entropy
Yara detected LockBit ransomware
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1357111 Sample: SecuriteInfo.com.Trojan.Enc... Startdate: 10/12/2023 Architecture: WINDOWS Score: 100 54 Multi AV Scanner detection for domain / URL 2->54 56 Antivirus detection for URL or domain 2->56 58 Antivirus / Scanner detection for submitted sample 2->58 60 3 other signatures 2->60 7 loaddll64.exe 23 1 2->7         started        process3 file4 34 C:\Program Files (x86)\...\OFFSYMXL.TTF, DOS 7->34 dropped 36 C:\Program Files (x86)\...\MLCFG32.CPL, DOS 7->36 dropped 38 C:\...\VisioPro2019R_Grace-ppd.xrm-ms, DOS 7->38 dropped 40 231 other files (226 malicious) 7->40 dropped 70 Found potential ransomware demand text 7->70 72 Found Tor onion address 7->72 74 Writes many files with high entropy 7->74 11 cmd.exe 1 7->11         started        13 rundll32.exe 8 7->13         started        17 conhost.exe 7->17         started        19 rundll32.exe 7->19         started        signatures5 process6 file7 21 rundll32.exe 35 11->21         started        42 C:\Program Files\7-Zip\readme.txt, data 13->42 dropped 44 C:\Program Files (x86)\...\OSPP.HTM, data 13->44 dropped 46 C:\Program Files (x86)\Java\...\Welcome.html, data 13->46 dropped 76 Found potential ransomware demand text 13->76 78 Found Tor onion address 13->78 80 Infects executable files (exe, dll, sys, html) 13->80 signatures8 process9 dnsIp10 48 192.168.2.100 unknown unknown 21->48 50 192.168.2.101 unknown unknown 21->50 52 98 other IPs or domains 21->52 26 C:\Program Files\7-Zip\Lang\an.txt, DOS 21->26 dropped 28 C:\Program Files (x86)\...\WordConstants.au3, 370 21->28 dropped 30 C:\...\ProcessConstants.au3, COM 21->30 dropped 32 9 other files (none is malicious) 21->32 dropped 62 System process connects to network (likely due to code injection or exploit) 21->62 64 Connects to many different private IPs via SMB (likely to spread or exploit) 21->64 66 Connects to many different private IPs (likely to spread or exploit) 21->66 68 2 other signatures 21->68 file11 signatures12
Threat name:
Win64.Downloader.BazaarLoader
Status:
Malicious
First seen:
2023-08-15 16:17:06 UTC
File Type:
PE+ (Dll)
AV detection:
23 of 37 (62.16%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Drops file in Program Files directory
Drops desktop.ini file(s)
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
49e891411c7eb5d49fd52c738dd664879d2b1d6bcb090ce6aeaa0b6342c1ecdc
MD5 hash:
32cdf76f81e20483f45317febc1ed085
SHA1 hash:
c68437dc84c22f05ab08ffb1fa56cd752bf51862
Detections:
ContiRansomware
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:RAN_Lockbit_Green_Jan_2023_2
Author:Arkbird_SOLG
Description:Detect the green variant used by lockbit group (x64)
Reference:https://github.com/prodaft/malware-ioc/blob/master/LockBit/green.md

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments