🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5ea463e0719ee2d1705ff305cdd8529bd2ff23dde79c502c4f478937a91f874. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 10


Intelligence 10 IOCs YARA 9 File information Comments 1

SHA256 hash: d5ea463e0719ee2d1705ff305cdd8529bd2ff23dde79c502c4f478937a91f874
SHA3-384 hash: a9e4511cfc24761030daf9539612eaf26598d562dcf129238550473df8689bd43bb10e98536ac3d2f938756b9e2c95aa
SHA1 hash: db0731d693a1ac46706825dcb91193ae4efec482
MD5 hash: b3175331ae74ee277e94d3e0bc982bf4
humanhash: nevada-virginia-eleven-romeo
File name:b3175331_by_Libranalysis
Download: download sample
Signature LockBit
File size:149'504 bytes
First seen:2021-05-06 14:01:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e9f710b579880d1b6ff748176eb620f1 (4 x LockBit)
ssdeep 3072:V6ZkRGjkBrmKmY99UpkD1/34bIpVSrtLmqc2LVMMqqD/h2LuTeONA5tIHVc:IS9rLPPUpa3VVEtLXcCqqD/hOQnaMc
Threatray 9 similar samples on MalwareBazaar
TLSH E0E32725F156E276C4E70BB07668CFF658E8A434232090F7DBED0A5C18E4BE16E37256
Reporter Libranalysis
Tags:lockbit


Avatar
Libranalysis
Uploaded as part of the sample sharing project

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'519
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
8B87A11BCEAB4AA5.exe
Verdict:
Malicious activity
Analysis date:
2021-05-06 13:36:28 UTC
Tags:
ransomware lockbit

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changing a file
Running batch commands
Creating a process with a hidden window
Creating a file
Creating a file in the Program Files subdirectories
Moving a file to the Program Files subdirectory
Modifying an executable file
Launching a service
Launching a process
Creating a file in the Windows subdirectories
Creating a window
Sending a UDP request
Using the Windows Management Instrumentation requests
Connection attempt
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Creating a file in the mass storage device
Deleting volume shadow copies
Preventing system recovery
Forced shutdown of a browser
Encrypting user's files
Result
Threat name:
LockBit ransomware
Detection:
malicious
Classification:
rans.spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Contains functionality to hide a thread from the debugger
Contains functionalty to change the wallpaper
Creates files inside the volume driver (system volume information)
Deletes shadow drive data (may be related to ransomware)
Deletes the backup plan of Windows
Found ransom note / readme
Found Tor onion address
Hides threads from debuggers
Machine Learning detection for sample
May disable shadow drive data (uses vssadmin)
Modifies existing user documents (likely ransomware behavior)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: Copying Sensitive Files with Credential Data
Sigma detected: Modification of Boot Configuration
Sigma detected: Shadow Copies Deletion Using Operating Systems Utilities
Sigma detected: WannaCry Ransomware
Spreads via windows shares (copies files to share folders)
Uses bcdedit to modify the Windows boot settings
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Yara detected LockBit ransomware
Yara detected RansomwareGeneric
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 407189 Sample: b3175331_by_Libranalysis Startdate: 07/05/2021 Architecture: WINDOWS Score: 100 67 Multi AV Scanner detection for domain / URL 2->67 69 Sigma detected: WannaCry Ransomware 2->69 71 Antivirus / Scanner detection for submitted sample 2->71 73 10 other signatures 2->73 7 b3175331_by_Libranalysis.exe 7 189 2->7         started        12 b3175331_by_Libranalysis.exe 2->12         started        14 b3175331_by_Libranalysis.exe 2->14         started        16 3 other processes 2->16 process3 dnsIp4 61 192.168.2.100 unknown unknown 7->61 63 192.168.2.101 unknown unknown 7->63 65 98 other IPs or domains 7->65 45 C:\Users\user\...\spartan.edb, data 7->45 dropped 47 C:\Users\user\...\edb00002.log, data 7->47 dropped 49 C:\Users\user\...\edb00001.log, data 7->49 dropped 57 110 other malicious files 7->57 dropped 83 Contains functionalty to change the wallpaper 7->83 85 Deletes shadow drive data (may be related to ransomware) 7->85 87 Writes a notice file (html or txt) to demand a ransom 7->87 101 3 other signatures 7->101 18 cmd.exe 1 7->18         started        21 conhost.exe 7->21         started        51 C:\Program Files\...\resources.b461fb38.pri, data 12->51 dropped 53 C:\Program Files\...\AppxBlockMap.xml, data 12->53 dropped 55 C:\Program Files\...\AppxBundleManifest.xml, data 12->55 dropped 59 32 other malicious files 12->59 dropped 89 Spreads via windows shares (copies files to share folders) 12->89 91 Hides threads from debuggers 12->91 23 conhost.exe 12->23         started        93 Connects to many different private IPs via SMB (likely to spread or exploit) 14->93 95 Connects to many different private IPs (likely to spread or exploit) 14->95 97 Uses bcdedit to modify the Windows boot settings 14->97 25 cmd.exe 14->25         started        27 conhost.exe 14->27         started        99 Creates files inside the volume driver (system volume information) 16->99 file5 signatures6 process7 signatures8 75 May disable shadow drive data (uses vssadmin) 18->75 77 Deletes shadow drive data (may be related to ransomware) 18->77 79 Uses bcdedit to modify the Windows boot settings 18->79 29 bcdedit.exe 1 18->29         started        31 bcdedit.exe 1 18->31         started        33 WMIC.exe 1 18->33         started        41 3 other processes 18->41 81 Deletes the backup plan of Windows 25->81 35 conhost.exe 25->35         started        37 vssadmin.exe 25->37         started        39 WMIC.exe 25->39         started        43 3 other processes 25->43 process9
Threat name:
Win32.Ransomware.LockBit
Status:
Malicious
First seen:
2021-05-06 14:02:10 UTC
File Type:
PE (Exe)
AV detection:
38 of 47 (80.85%)
Threat level:
  5/5
Result
Malware family:
lockbit
Score:
  10/10
Tags:
family:lockbit evasion persistence ransomware
Behaviour
Checks SCSI registry key(s)
Interacts with shadow copies
Modifies Control Panel
Modifies Internet Explorer settings
Modifies registry class
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Sets desktop wallpaper using registry
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Drops desktop.ini file(s)
Enumerates connected drives
Deletes itself
Deletes backup catalog
Modifies extensions of user files
Deletes shadow copies
Modifies boot configuration data using bcdedit
Lockbit
Unpacked files
SH256 hash:
d5ea463e0719ee2d1705ff305cdd8529bd2ff23dde79c502c4f478937a91f874
MD5 hash:
b3175331ae74ee277e94d3e0bc982bf4
SHA1 hash:
db0731d693a1ac46706825dcb91193ae4efec482
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:crime_win32_ransom_lockbit_1
Author:@VK_Intel
Description:Detects LockBit ransomware
Reference:twitter
Rule name:INDICATOR_SUSPICIOUS_ClearWinLogs
Author:ditekSHen
Description:Detects executables containing commands for clearing Windows Event Logs
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:INDICATOR_SUSPICIOUS_GENRansomware
Author:ditekSHen
Description:detects command variations typically used by ransomware
Rule name:INDICATOR_SUSPICIOUS_USNDeleteJournal
Author:ditekSHen
Description:Detects executables containing anti-forensic artifcats of deletiing USN change journal. Observed in ransomware
Rule name:INDICATOR_SUSPICOUS_EXE_References_VEEAM
Description:Detects executables containing many references to VEEAM. Observed in ransomware
Rule name:Lockbit
Author:kevoreilly
Description:Lockbit Payload
Rule name:UAC_bypass_bin_mem
Author:James_inthe_box
Description:UAC bypass in files like avemaria

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-06 16:45:09 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [B0001.036] Anti-Behavioral Analysis::Process Environment Block NtGlobalFlag
1) [B0001.032] Anti-Behavioral Analysis::Timing/Delay Check GetTickCount
2) [B0009] Anti-Behavioral Analysis::Virtual Machine Detection
3) [B0012.001] Anti-Static Analysis::Argument Obfuscation
4) [C0001.004] Communication Micro-objective::Connect Socket::Socket Communication
5) [C0001.011] Communication Micro-objective::Create TCP Socket::Socket Communication
6) [C0001.012] Communication Micro-objective::Get Socket Status::Socket Communication
7) [C0001.009] Communication Micro-objective::Initialize Winsock Library::Socket Communication
8) [C0001.001] Communication Micro-objective::Set Socket Config::Socket Communication
9) [C0001.008] Communication Micro-objective::TCP Client::Socket Communication
10) [C0029.004] Cryptography Micro-objective::SHA224::Cryptographic Hash
11) [C0029.003] Cryptography Micro-objective::SHA256::Cryptographic Hash
12) [C0027.001] Cryptography Micro-objective::AES::Encrypt Data
13) [C0021.003] Cryptography Micro-objective::Use API::Generate Pseudo-random Sequence
14) [C0026.002] Data Micro-objective::XOR::Encode Data
15) [C0030.001] Data Micro-objective::MurmurHash::Non-Cryptographic Hash
18) [C0047] File System Micro-objective::Delete File
19) [C0049] File System Micro-objective::Get File Attributes
20) [C0051] File System Micro-objective::Read File
21) [C0050] File System Micro-objective::Set File Attributes
22) [C0052] File System Micro-objective::Writes File
23) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
24) [C0036.007] Operating System Micro-objective::Delete Registry Value::Registry
25) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
26) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
27) [C0036.001] Operating System Micro-objective::Set Registry Key::Registry
28) [C0035] Operating System Micro-objective::Wallpaper
29) [C0043] Process Micro-objective::Check Mutex
30) [C0042] Process Micro-objective::Create Mutex
31) [C0017] Process Micro-objective::Create Process
32) [C0038] Process Micro-objective::Create Thread
33) [C0018] Process Micro-objective::Terminate Process