🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee3e03f4510a1a325a06a17060a89da7ae5f9b805e4fe3a8c78327b9ecae84df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ee3e03f4510a1a325a06a17060a89da7ae5f9b805e4fe3a8c78327b9ecae84df
SHA3-384 hash: 630bb6595667114a1dc4beab9623c51b459119fe04a9a874d3a015baab05fcc0ab435eb75c633e0acf571be617ed2477
SHA1 hash: a118e1e110e285fb82495defe7d1c570d922ee0d
MD5 hash: 3c9e550d41f3de930e678776a6e018ed
humanhash: glucose-magazine-pizza-seventeen
File name:ee3e03f4510a1a325a06a17060a89da7ae5f9b805e4fe3a8c78327b9ecae84df
Download: download sample
Signature LockBit
File size:260'872 bytes
First seen:2022-01-27 03:41:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 6144:oJl8NceL9UdcOK7qKx4XY+5z8WtlqqD4qgf2bcAf:o/8NcFlpNBtIqPg+bcA
TLSH T100448D0FB456A4BDC1ABE830D6DF9AB296293DDD472439373242E9313423BA46F19F41
telfhash t1e601dd0de93c07dc48826c24c84d8b8341abd62b4079f604ff99dcd04a6d91af338c5a
Reporter Jirehlov
Tags:elf lockbit Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
936
Origin country :
n/a
Vendor Threat Intelligence
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
CPUID_Instruction
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
packed
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
8
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-Debugging
Process Inject
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Threat name:
LockBit ransomware
Detection:
malicious
Classification:
rans.evad
Score:
56 / 100
Signature
Found Tor onion address
Machine Learning detection for sample
Yara detected LockBit ransomware
Behaviour
Behavior Graph:
Threat name:
Linux.Ransomware.LockBit
Status:
Malicious
First seen:
2021-12-30 21:48:08 UTC
File Type:
ELF64 Little (Exe)
AV detection:
13 of 27 (48.15%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments