🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 925191be26b5087f04a6616fae9fbb71b8e09f80591cf4608d49076a5c0015ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 925191be26b5087f04a6616fae9fbb71b8e09f80591cf4608d49076a5c0015ca
SHA3-384 hash: 0b1d356b8d091260a9cb5948548ea2ff3af2894ed39b4036a6b3081ee3f808ad0822a10379d0e3facedcb5bbedc20e58
SHA1 hash: 4cda73d646e70285b57271a70147ce94eb6d9a12
MD5 hash: fb2abd79a35cf5137d5998d77bc2cb19
humanhash: arizona-grey-music-colorado
File name:LBB_PS1_obfuscated.ps1
Download: download sample
Signature LockBit
File size:1'137'671 bytes
First seen:2023-05-03 03:34:14 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 12288:NZu4LmkiVF5Kk5MGx2kFVTxQkOK6XGtRLD5Wc:NZok6F5KS71VT3AX8RLdWc
TLSH T1FC354CF35320E8FA72D668523294920EB7CF33BB1B450EC0B577A5C952656D88F1C4EA
Reporter petikvx
Tags:lockbit

Intelligence


File Origin
# of uploads :
1
# of downloads :
393
Origin country :
FR FR
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
lockbit powershell
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 858073 Sample: LBB_PS1_obfuscated.ps1 Startdate: 03/05/2023 Architecture: WINDOWS Score: 48 15 Multi AV Scanner detection for submitted file 2->15 7 powershell.exe 21 2->7         started        process3 process4 9 powershell.exe 7 7->9         started        11 conhost.exe 7->11         started        process5 13 conhost.exe 9->13         started       
Threat name:
Win32.Ransomware.Lockbit
Status:
Suspicious
First seen:
2023-04-29 23:10:07 UTC
File Type:
Text (PowerShell)
AV detection:
9 of 37 (24.32%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
lockbit
Score:
  10/10
Tags:
family:lockbit ransomware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Drops file in System32 directory
Sets desktop wallpaper using registry
Suspicious use of NtSetInformationThreadHideFromDebugger
Executes dropped EXE
Lockbit
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:HUN_Exchange_Gold_Mystic_Oct_2022_1
Author:Arkbird_SOLG
Description:Detect the implant used against vulnerable Exchange servers by the Gold Mystic group (Lockbit)
Reference:https://asec.ahnlab.com/ko/39682/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments