🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87e2e3291268aa3e203cfe917ee7974926bcab7d3b0f417b7b2ede4acfd2869f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 87e2e3291268aa3e203cfe917ee7974926bcab7d3b0f417b7b2ede4acfd2869f
SHA3-384 hash: 41c0aa94cdd316e0b27b096fb71cd4de99808cd76259c3ade1b7c4f4dfa24f8b5120d91735bec115e2dcbdfa29c5e371
SHA1 hash: 5723299076c4a032cda695ce74ef6e54f9ab2f52
MD5 hash: 4b6a088568f7293969566b7bdaf58741
humanhash: failed-don-fanta-sierra
File name:김기환.docx
Download: download sample
Signature LockBit
File size:159'288 bytes
First seen:2022-12-01 13:54:56 UTC
Last seen:Never
File type:Word file docx
MIME type:application/zip
ssdeep 3072:HKPNqHlnUjeb+oBlRvDNRmc95BR/YCkXr03++0CN:qPNqNmW+2RvDvJF/YCY2HN
TLSH T184F31279C16E69E1C10A9739BEC17EC6A759275299D8DB0E0EF7728C0390CD5B933132
TrID 51.0% (.DOCX) Word Microsoft Office Open XML Format document (23500/1/4)
38.0% (.ZIP) Open Packaging Conventions container (17500/1/4)
8.6% (.ZIP) ZIP compressed archive (4000/1)
2.1% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:docx lockbit

Intelligence


File Origin
# of uploads :
1
# of downloads :
556
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
김기환.docx
Verdict:
Malicious activity
Analysis date:
2022-12-01 14:01:14 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Creating a window
Searching for synchronization primitives
Сreating synchronization primitives
Creating a file
Result
Verdict:
Malicious
File Type:
OOXML Word File
Payload URLs
URL
File name
https://transfer.sh/get/KgHDsr/s3g53o.dotm
settings.xml.rels
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd CVE-2017-0199 exploit macros macros-on-open powershell
Label:
Malicious
Suspicious Score:
9.9/10
Score Malicious:
1%
Score Benign:
0%
Result
Threat name:
Conti, LockBit ransomware
Detection:
malicious
Classification:
expl.evad.rans.spre
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Contains an external reference to another file
Contains functionality to hide a thread from the debugger
Creates autostart registry keys with suspicious names
Deletes shadow drive data (may be related to ransomware)
Document contains an embedded VBA macro which may execute processes
Document exploit detected (process start blacklist hit)
Drops PE files to the user root directory
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found ransom note / readme
Found Tor onion address
Hides threads from debuggers
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
May disable shadow drive data (uses vssadmin)
Multi AV Scanner detection for submitted file
Obfuscated command line found
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Powershell drops PE file
Sigma detected: Delete shadow copy via WMIC
Spreads via windows shares (copies files to share folders)
Uses bcdedit to modify the Windows boot settings
Writes a notice file (html or txt) to demand a ransom
Yara detected Conti ransomware
Yara detected LockBit ransomware
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 758215 Sample: #Uae40#Uae30#Ud658.docx Startdate: 01/12/2022 Architecture: WINDOWS Score: 100 83 Malicious sample detected (through community Yara rule) 2->83 85 Antivirus detection for URL or domain 2->85 87 Multi AV Scanner detection for submitted file 2->87 89 12 other signatures 2->89 11 WINWORD.EXE 67 63 2->11         started        15 fdjk483u9rey89t53e.exe 17 2->15         started        18 fdjk483u9rey89t53e.exe 2->18         started        process3 dnsIp4 81 transfer.sh 11->81 107 Obfuscated command line found 11->107 20 cmd.exe 1 11->20         started        22 MSOSYNC.EXE 5 12 11->22         started        24 MSOSYNC.EXE 2 3 11->24         started        69 C:\Users\user\AppData\Local\...\System.dll, PE32 15->69 dropped 71 C:\Users\user\AppData\Local\...\System.dll, PE32 18->71 dropped file5 signatures6 process7 process8 26 powershell.exe 15 14 20->26         started        31 conhost.exe 20->31         started        dnsIp9 79 transfer.sh 26->79 67 C:\Users\Public\fdjk483u9rey89t53e.exe, PE32 26->67 dropped 109 Drops PE files to the user root directory 26->109 111 Powershell drops PE file 26->111 33 fdjk483u9rey89t53e.exe 18 26->33         started        file10 signatures11 process12 file13 57 C:\Users\user\AppData\Local\...\System.dll, PE32 33->57 dropped 91 Antivirus detection for dropped file 33->91 93 Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors) 33->93 95 Deletes shadow drive data (may be related to ransomware) 33->95 97 5 other signatures 33->97 37 fdjk483u9rey89t53e.exe 8 63 33->37         started        42 WerFault.exe 3 33->42         started        44 WerFault.exe 33->44         started        signatures14 process15 dnsIp16 73 192.168.2.100 unknown unknown 37->73 75 192.168.2.101 unknown unknown 37->75 77 98 other IPs or domains 37->77 59 C:\Program Files\UNP\...\Restore-My-Files.txt, ASCII 37->59 dropped 61 C:\Program Files\UNP\...\Restore-My-Files.txt, ASCII 37->61 dropped 63 C:\Program Files\...\Restore-My-Files.txt, ASCII 37->63 dropped 65 7 other malicious files 37->65 dropped 99 Connects to many different private IPs via SMB (likely to spread or exploit) 37->99 101 Connects to many different private IPs (likely to spread or exploit) 37->101 103 Creates autostart registry keys with suspicious names 37->103 105 4 other signatures 37->105 46 cmd.exe 1 37->46         started        file17 signatures18 process19 signatures20 113 May disable shadow drive data (uses vssadmin) 46->113 115 Deletes shadow drive data (may be related to ransomware) 46->115 117 Uses bcdedit to modify the Windows boot settings 46->117 49 conhost.exe 46->49         started        51 vssadmin.exe 1 46->51         started        53 WMIC.exe 46->53         started        55 2 other processes 46->55 process21
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Abuses OpenXML format to download file from external location
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments