🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9ee359288d73ab0b0f2fabb03bc24dd166aef946fd863d0f1d68b6f99079830. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: b9ee359288d73ab0b0f2fabb03bc24dd166aef946fd863d0f1d68b6f99079830
SHA3-384 hash: 4f31033a098cf30ef240121071f9132b5b4ec08669541304d1a54b4fdd63cd857c54744328da66bdde093e15e2beb59e
SHA1 hash: 734cad8d984774c14367aacf9a3d35979fbfc94d
MD5 hash: 9f80a3584dd2c3c44b307f0c0a6ca1e6
humanhash: charlie-finch-alaska-william
File name:임범수.docx
Download: download sample
Signature LockBit
File size:159'290 bytes
First seen:2022-12-05 09:01:32 UTC
Last seen:Never
File type:Word file docx
MIME type:application/zip
ssdeep 3072:HKPNqHlnUjeb+oBlRvDNRmc95BR/YCkXr03++04:qPNqNmW+2RvDvJF/YCY2F
TLSH T1F8F31275C16E69E1C10AD739BFC13EC6E7582792A9D89B0E1EE7728C07809D5B932132
TrID 51.0% (.DOCX) Word Microsoft Office Open XML Format document (23500/1/4)
38.0% (.ZIP) Open Packaging Conventions container (17500/1/4)
8.6% (.ZIP) ZIP compressed archive (4000/1)
2.1% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:cve-2017-0199 docx lockbit

Intelligence


File Origin
# of uploads :
1
# of downloads :
643
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
DNS request
Creating a window
Searching for synchronization primitives
Сreating synchronization primitives
Creating a file
Sending a custom TCP request
Launching a process
Creating a process from a recently created file
Result
Verdict:
Malicious
File Type:
OOXML Word File
Payload URLs
URL
File name
https://transfer.sh/get/KgHDsr/s3g53o.dotm
settings.xml.rels
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd macros macros-on-open powershell
Label:
Malicious
Suspicious Score:
9.9/10
Score Malicious:
1%
Score Benign:
0%
Result
Threat name:
LockBit ransomware
Detection:
malicious
Classification:
expl.evad.rans.spre
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Contains an external reference to another file
Contains functionality to hide a thread from the debugger
Creates autostart registry keys with suspicious names
Deletes shadow drive data (may be related to ransomware)
Document contains an embedded VBA macro which may execute processes
Document exploit detected (process start blacklist hit)
Drops PE files to the user root directory
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Found ransom note / readme
Found Tor onion address
Hides threads from debuggers
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
May disable shadow drive data (uses vssadmin)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Obfuscated command line found
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Powershell drops PE file
Sigma detected: Delete shadow copy via WMIC
Spreads via windows shares (copies files to share folders)
Uses bcdedit to modify the Windows boot settings
Writes a notice file (html or txt) to demand a ransom
Yara detected LockBit ransomware
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 760703 Sample: #Uc784#Ubc94#Uc218.docx Startdate: 05/12/2022 Architecture: WINDOWS Score: 100 83 Multi AV Scanner detection for domain / URL 2->83 85 Malicious sample detected (through community Yara rule) 2->85 87 Antivirus detection for URL or domain 2->87 89 12 other signatures 2->89 11 WINWORD.EXE 76 69 2->11         started        15 fdjk483u9rey89t53e.exe 2->15         started        18 fdjk483u9rey89t53e.exe 2->18         started        process3 dnsIp4 81 transfer.sh 11->81 107 Obfuscated command line found 11->107 20 cmd.exe 1 11->20         started        22 MSOSYNC.EXE 5 12 11->22         started        24 MSOSYNC.EXE 2 3 11->24         started        69 C:\Users\user\AppData\Local\...\System.dll, PE32 15->69 dropped 71 C:\Users\user\AppData\Local\...\System.dll, PE32 18->71 dropped file5 signatures6 process7 process8 26 powershell.exe 15 16 20->26         started        31 conhost.exe 20->31         started        dnsIp9 79 transfer.sh 26->79 67 C:\Users\Public\fdjk483u9rey89t53e.exe, PE32 26->67 dropped 109 Drops PE files to the user root directory 26->109 111 Powershell drops PE file 26->111 33 fdjk483u9rey89t53e.exe 18 26->33         started        file10 signatures11 process12 file13 57 C:\Users\user\AppData\Local\...\System.dll, PE32 33->57 dropped 91 Antivirus detection for dropped file 33->91 93 Multi AV Scanner detection for dropped file 33->93 95 Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors) 33->95 97 6 other signatures 33->97 37 fdjk483u9rey89t53e.exe 8 224 33->37         started        42 WerFault.exe 33->42         started        44 WerFault.exe 33->44         started        signatures14 process15 dnsIp16 73 192.168.2.100 unknown unknown 37->73 75 192.168.2.101 unknown unknown 37->75 77 98 other IPs or domains 37->77 59 C:\...\Restore-My-Files.txt, ASCII 37->59 dropped 61 C:\...\Restore-My-Files.txt, ASCII 37->61 dropped 63 C:\...\Restore-My-Files.txt, ASCII 37->63 dropped 65 7 other malicious files 37->65 dropped 99 Connects to many different private IPs via SMB (likely to spread or exploit) 37->99 101 Connects to many different private IPs (likely to spread or exploit) 37->101 103 Creates autostart registry keys with suspicious names 37->103 105 4 other signatures 37->105 46 cmd.exe 1 37->46         started        file17 signatures18 process19 signatures20 113 May disable shadow drive data (uses vssadmin) 46->113 115 Deletes shadow drive data (may be related to ransomware) 46->115 117 Uses bcdedit to modify the Windows boot settings 46->117 49 conhost.exe 46->49         started        51 vssadmin.exe 1 46->51         started        53 WMIC.exe 1 46->53         started        55 2 other processes 46->55 process21
Threat name:
Document-Office.Exploit.CVE-2017-0199
Status:
Malicious
First seen:
2022-12-01 05:33:25 UTC
File Type:
Document
Extracted files:
24
AV detection:
12 of 26 (46.15%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Abuses OpenXML format to download file from external location
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments