🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa0eaa5d9c3d0632486c2de49aaf3e40bb1d7a8fcb434761abebaa0d7cd04598. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 10


Maldoc score: 9


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: aa0eaa5d9c3d0632486c2de49aaf3e40bb1d7a8fcb434761abebaa0d7cd04598
SHA3-384 hash: 098e75866e75e2f8e04be9d28b9c371fb3ac54403817e00bd41896c95d4d628fe858909baad183781f205b2da0164257
SHA1 hash: b3e7eec3f8770449ac4d2c724a85dca66601d686
MD5 hash: d110002b1fc1ffb8265e0b10f9e05013
humanhash: single-oranges-yellow-music
File name:s3g53o.dotm
Download: download sample
Signature LockBit
File size:16'425 bytes
First seen:2022-12-01 14:44:30 UTC
Last seen:Never
File type:Word file doc
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 384:tbftLQqLv7mAEmvMCnqNxt/ZtNNeEYMbVwfHbnvZ:51LXLvHUggxllNeEY4u1
TLSH T18B72C07CD524B419CA360D76C18F16B8F02801267615A46F3411C7FFEA355EB17253CD
TrID 53.0% (.DOCM) Word Microsoft Office Open XML Format document (with Macro) (52000/1/9)
23.9% (.DOCX) Word Microsoft Office Open XML Format document (23500/1/4)
17.8% (.ZIP) Open Packaging Conventions container (17500/1/4)
4.0% (.ZIP) ZIP compressed archive (4000/1)
1.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:doc lockbit

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 9
OLE dump

MalwareBazaar was able to identify 6 sections in this file using oledump:

Section IDSection sizeSection name
A1365 bytesPROJECT
A241 bytesPROJECTwm
A32404 bytesVBA/ThisDocument
A42523 bytesVBA/_VBA_PROJECT
A5469 bytesVBA/dir
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecDocument_OpenRuns when the Word or Publisher document is opened
IOCfdjk483u9rey89t53e.eExecutable file name
SuspiciousGetObjectMay get an OLE object with a running instance
SuspiciousexecMay run an executable file or a system
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
345
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
s3g53o.dotm
Verdict:
No threats detected
Analysis date:
2022-12-01 14:46:10 UTC
Tags:
macros macros-on-open

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
DNS request
Searching for the window
Creating a window
Сreating synchronization primitives
Result
Verdict:
Malicious
File Type:
Word File with Macro
Payload URLs
URL
File name
https://transfsy9cquuwr.sh/gsy9cquuwt/JQJU3c/fdrssy9cquuwtrgh.sy9cquuwxsy9cquuw
ThisDocument
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd macros macros-on-open powershell shell32.dll
Label:
Malicious
Suspicious Score:
7.4/10
Score Malicious:
74%
Score Benign:
26%
Result
Threat name:
LockBit ransomware
Detection:
malicious
Classification:
expl.rans.spre.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Contains functionality to hide a thread from the debugger
Creates autostart registry keys with suspicious names
Deletes shadow drive data (may be related to ransomware)
Document contains an embedded VBA macro which may execute processes
Document exploit detected (process start blacklist hit)
Drops PE files to the user root directory
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found ransom note / readme
Found Tor onion address
Hides threads from debuggers
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
May disable shadow drive data (uses vssadmin)
Multi AV Scanner detection for submitted file
Obfuscated command line found
Powershell drops PE file
Sigma detected: Delete shadow copy via WMIC
Spreads via windows shares (copies files to share folders)
Uses bcdedit to modify the Windows boot settings
Writes a notice file (html or txt) to demand a ransom
Yara detected LockBit ransomware
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 758185 Sample: s3g53o.dotm.doc Startdate: 01/12/2022 Architecture: WINDOWS Score: 100 156 Malicious sample detected (through community Yara rule) 2->156 158 Antivirus detection for URL or domain 2->158 160 Multi AV Scanner detection for submitted file 2->160 162 10 other signatures 2->162 11 WINWORD.EXE 32 28 2->11         started        14 fdjk483u9rey89t53e.exe 2->14         started        17 fdjk483u9rey89t53e.exe 2->17         started        19 fdjk483u9rey89t53e.exe 2->19         started        process3 file4 190 Obfuscated command line found 11->190 21 cmd.exe 1 11->21         started        23 cmd.exe 11->23         started        25 cmd.exe 11->25         started        29 8 other processes 11->29 126 C:\Users\user\AppData\Local\...\System.dll, PE32 14->126 dropped 192 Maps a DLL or memory area into another process 14->192 194 Injects a PE file into a foreign processes 14->194 27 fdjk483u9rey89t53e.exe 14->27         started        128 C:\Users\user\AppData\Local\...\System.dll, PE32 17->128 dropped 130 C:\Users\user\AppData\Local\...\System.dll, PE32 19->130 dropped signatures5 process6 process7 31 powershell.exe 15 17 21->31         started        36 conhost.exe 21->36         started        38 powershell.exe 23->38         started        40 conhost.exe 23->40         started        42 powershell.exe 25->42         started        44 conhost.exe 25->44         started        46 powershell.exe 29->46         started        48 powershell.exe 29->48         started        50 14 other processes 29->50 dnsIp8 138 transfer.sh 31->138 98 C:\Users\Public\fdjk483u9rey89t53e.exe, PE32 31->98 dropped 152 Drops PE files to the user root directory 31->152 154 Powershell drops PE file 31->154 52 fdjk483u9rey89t53e.exe 18 31->52         started        140 transfer.sh 38->140 56 fdjk483u9rey89t53e.exe 17 38->56         started        142 transfer.sh 42->142 58 fdjk483u9rey89t53e.exe 17 42->58         started        144 transfer.sh 46->144 60 fdjk483u9rey89t53e.exe 17 46->60         started        146 transfer.sh 48->146 62 fdjk483u9rey89t53e.exe 17 48->62         started        148 transfer.sh 50->148 150 5 other IPs or domains 50->150 64 fdjk483u9rey89t53e.exe 17 50->64         started        66 fdjk483u9rey89t53e.exe 50->66         started        68 fdjk483u9rey89t53e.exe 50->68         started        70 2 other processes 50->70 file9 signatures10 process11 file12 100 C:\Users\user\AppData\Local\...\System.dll, PE32 52->100 dropped 164 Antivirus detection for dropped file 52->164 166 Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors) 52->166 168 Deletes shadow drive data (may be related to ransomware) 52->168 174 3 other signatures 52->174 72 fdjk483u9rey89t53e.exe 52->72         started        77 WerFault.exe 52->77         started        79 WerFault.exe 52->79         started        102 C:\Users\user\AppData\Local\...\System.dll, PE32 56->102 dropped 170 Maps a DLL or memory area into another process 56->170 172 Injects a PE file into a foreign processes 56->172 81 fdjk483u9rey89t53e.exe 56->81         started        83 WerFault.exe 56->83         started        85 WerFault.exe 56->85         started        104 C:\Users\user\AppData\Local\...\System.dll, PE32 58->104 dropped 106 C:\Users\user\AppData\Local\...\System.dll, PE32 60->106 dropped 108 C:\Users\user\AppData\Local\...\System.dll, PE32 62->108 dropped 110 C:\Users\user\AppData\Local\...\System.dll, PE32 64->110 dropped 112 C:\Users\user\AppData\Local\...\System.dll, PE32 66->112 dropped 114 C:\Users\user\AppData\Local\...\System.dll, PE32 68->114 dropped 116 2 other files (none is malicious) 70->116 dropped signatures13 process14 dnsIp15 132 192.168.2.100 unknown unknown 72->132 134 192.168.2.101 unknown unknown 72->134 136 98 other IPs or domains 72->136 118 C:\...\s_anonymoususer_24.svg.lockbit, DOS 72->118 dropped 120 C:\...\large_trefoil.png.lockbit, DOS 72->120 dropped 122 C:\...\sendforcomments.svg.lockbit, COM 72->122 dropped 124 15 other malicious files 72->124 dropped 182 Connects to many different private IPs via SMB (likely to spread or exploit) 72->182 184 Connects to many different private IPs (likely to spread or exploit) 72->184 186 Creates autostart registry keys with suspicious names 72->186 188 4 other signatures 72->188 87 cmd.exe 72->87         started        file16 signatures17 process18 signatures19 176 May disable shadow drive data (uses vssadmin) 87->176 178 Deletes shadow drive data (may be related to ransomware) 87->178 180 Uses bcdedit to modify the Windows boot settings 87->180 90 conhost.exe 87->90         started        92 vssadmin.exe 87->92         started        94 WMIC.exe 87->94         started        96 2 other processes 87->96 process20
Threat name:
Script.Downloader.Powdow
Status:
Malicious
First seen:
2022-12-01 04:59:46 UTC
File Type:
Document
Extracted files:
20
AV detection:
12 of 26 (46.15%)
Threat level:
  3/5
Result
Malware family:
lockbit
Score:
  10/10
Tags:
family:lockbit discovery evasion persistence ransomware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Interacts with shadow copies
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Enumerates physical storage devices
Program crash
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Loads dropped DLL
Blocklisted process makes network request
Downloads MZ/PE file
Executes dropped EXE
Creates a large amount of network flows
Deletes shadow copies
Modifies boot configuration data using bcdedit
Lockbit
Process spawned unexpected child process
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
Rule name:vbaproject_bin
Author:CD_R0M_
Description:{76 62 61 50 72 6f 6a 65 63 74 2e 62 69 6e} is hex for vbaproject.bin. Macros are often used by threat actors. Work in progress - Ran out of time

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments