🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 742489bd828bdcd5caaed00dccdb7a05259986801bfd365492714746cb57eb55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: 742489bd828bdcd5caaed00dccdb7a05259986801bfd365492714746cb57eb55
SHA3-384 hash: 1758f56c3fdfaea4484237c9476864c4530b76e4223f17f3f9b9c33bdaa6bc10da73bfda1b7368af1aef8437b8e34d80
SHA1 hash: 2a4f6fea8b4e726d01b0d1b1e629d3a392e063c1
MD5 hash: 32844e92bbd498244e3a2d8486181ae4
humanhash: indigo-speaker-emma-saturn
File name:742489bd828bdcd5caaed00dccdb7a05259986801bfd365492714746cb57eb55.bin
Download: download sample
Signature LockBit
File size:166'400 bytes
First seen:2022-07-16 20:36:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 50e4645798779602979868f1b8517523 (2 x LockBit)
ssdeep 3072:e6u2G0diw9r2iyJE/rdfzGO8EhwJYWB475vj0na8BY2TgJn54QEHdM2uoecqwZ:P1L9Byo5fzGO8EcNK75vYVTED/E9M2uS
Threatray 5 similar samples on MalwareBazaar
TLSH T1CCF31216EA7097AEC681A97703992083CD24DC7D0083542766FD827CBCECB1B6D727D8
TrID 27.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
20.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.5% (.EXE) Win32 Executable (generic) (4505/5/1)
8.5% (.EXE) Win16/32 Executable Delphi generic (2072/23)
8.3% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Arkbird_SOLG
Tags:exe lockbit lockbit black Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
877
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Searching for the window
Gathering data
Malware family:
LockBit Ransomware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.GenericML
Status:
Malicious
First seen:
2022-07-09 01:02:18 UTC
File Type:
PE (Exe)
AV detection:
17 of 26 (65.38%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
742489bd828bdcd5caaed00dccdb7a05259986801bfd365492714746cb57eb55
MD5 hash:
32844e92bbd498244e3a2d8486181ae4
SHA1 hash:
2a4f6fea8b4e726d01b0d1b1e629d3a392e063c1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:LockbitBlack_Loader
Author:Zander Work
Description:Hunting rule for the Lockbit Black loader, based on https://twitter.com/vxunderground/status/1543661557883740161
Rule name:LockbitBlack_Loader_Rule
Author:Luis Fabuel
Description:Hunting rule for the Lockbit Black loader, based on https://twitter.com/vxunderground/status/1543661557883740161
Rule name:RANSOM_Lockbit_Black_Packer
Author:SECUINFRA Falcon Team
Description:Detects the packer used by Lockbit Black (Version 3)
Reference:https://twitter.com/vxunderground/status/1543661557883740161
Rule name:V3_Lockbit_Black_Packer
Author:Luis F.R
Description:Detects the packer used by Lockbit Black (Version 3)
Reference:https://twitter.com/vxunderground/status/1543661557883740161

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments