🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f3a1576837ed56bcf79ff486aadf36e78d624853e9409ec1823a6f46fd0143ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f3a1576837ed56bcf79ff486aadf36e78d624853e9409ec1823a6f46fd0143ea
SHA3-384 hash: 791b3216cf49d8fc1e5dbf45dbadb7f1793c081408b8968e5bbf093d481dfbf1c8c69da65285e42e095f3a6f0fc8dc3c
SHA1 hash: 7e303af8c686a0c98fa87a34de1ffcf08f64a093
MD5 hash: 18a352d33c8c01b6a196adce176c5a96
humanhash: high-sad-alanine-shade
File name:f3a1576837ed56bcf79ff486aadf36e78d624853e9409ec1823a6f46fd0143ea
Download: download sample
Signature LockBit
File size:252'680 bytes
First seen:2022-01-27 03:42:17 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 6144:ZRXVXgUdcaDfqrKDXI+55fyplqqD4qgf2b:ZRVBb5P6pIqPg+b
TLSH T17A347D0FB496A47DC0ABE830D7DF9572A9257DCD87183A373242A9313527B942F1AF42
telfhash t103f0ac0da93d06dd88416c24c8098b83409bd77b40b9f505ff89dcd00a6d91ef234c5a
Reporter Jirehlov
Tags:elf lockbit Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
990
Origin country :
n/a
Vendor Threat Intelligence
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
CPUID_Instruction
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
packed
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
10
Number of processes launched:
3
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Anti-Debugging
Process Inject
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Threat name:
LockBit ransomware
Detection:
malicious
Classification:
rans.evad
Score:
64 / 100
Signature
Found Tor onion address
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Yara detected LockBit ransomware
Behaviour
Behavior Graph:
Threat name:
Linux.Ransomware.LockBit
Status:
Malicious
First seen:
2021-10-18 12:58:50 UTC
File Type:
ELF64 Little (Exe)
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
linux
Behaviour
Writes file to tmp directory
Reads CPU attributes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments