🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da443217cb10bdc98409fa3620b5eb6a906bd7ac9d879083b0bc44bf31355fb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: da443217cb10bdc98409fa3620b5eb6a906bd7ac9d879083b0bc44bf31355fb3
SHA3-384 hash: 0130720cdc2d6af3db897357b2aa1a30f3e1fb9f73a748229e86b2ff7ee6d589c4d59edf8eed87d2c41316eeeffe14ab
SHA1 hash: 80578ef5e60ab3d8fa008b591102213376ff5ea8
MD5 hash: 43059669c7e2082eca14dd626869363d
humanhash: berlin-golf-michigan-carbon
File name:a736269f5f3a9f2e11dd776e352e1801bc28bb699e47876784b8ef761e0062db.bin.sample.gz
Download: download sample
Signature LockBit
File size:277'107 bytes
First seen:2022-10-20 11:24:28 UTC
Last seen:2022-10-20 11:25:50 UTC
File type: gz
MIME type:application/gzip
ssdeep 6144:P42LBVCsV+PkMeW9zTiY/NaQmHst5ySPzmcfIMwma7:P4EzwkMeWgY1NmyESPB1/a7
TLSH T1AD4423070E35D9CDFB2CB773585888E4DDA6CBF7F84B5D9AE052D2B0926E8181642E21
Reporter realperumalj
Tags:Builder gz lockbit Ransomware


Avatar
realperumalj
LockBit v3 Ransomware Builder leaked by disgruntled LockBit member.

Intelligence


File Origin
# of uploads :
2
# of downloads :
610
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm filecoder lockbit packed packed ransomware shell32.dll spyeye windows
Threat name:
Win32.Ransomware.BlackMatter
Status:
Malicious
First seen:
2022-09-25 09:00:07 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
22 of 26 (84.62%)
Threat level:
  5/5
Result
Malware family:
blackmatter
Score:
  10/10
Tags:
family:blackmatter
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments