🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f9b9d45339db9164a3861bf61758b7f41e6bcfb5bc93404e296e2918e52ccc10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LockBit


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: f9b9d45339db9164a3861bf61758b7f41e6bcfb5bc93404e296e2918e52ccc10
SHA3-384 hash: 97fd86a09d2cbb35033d1ce9b7de68202601c03e226c77946f0aae590e871ce7248cd778e28e2c9cafdffdbaf4951413
SHA1 hash: ced1c9fabfe7e187dd809e77c9ca28ea2e165fa8
MD5 hash: 7fb11398c5be61445bee1efa7c9caa31
humanhash: spaghetti-shade-cup-india
File name:f9b9d45339db9164a3861bf61758b7f41e6bcfb5bc93404e296e2918e52ccc10.bin
Download: download sample
Signature LockBit
File size:166'400 bytes
First seen:2022-07-16 20:37:02 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 50e4645798779602979868f1b8517523 (2 x LockBit)
ssdeep 3072:hM38OugiM3koBZl6kpfxrgNYddVPkW8XeoSseFciJta6IR/o6BTREgDfBcKL8xDl:hjOugiM3koBDxrGyPktV1eRSZ17DfyKa
Threatray 6 similar samples on MalwareBazaar
TLSH T1F7F3129F711A565FE84742FE5B05F89039857F8D926C81B0E2F88D7E721CF99C010A9B
TrID 27.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
20.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
18.5% (.EXE) Win32 Executable (generic) (4505/5/1)
8.5% (.EXE) Win16/32 Executable Delphi generic (2072/23)
8.3% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter Arkbird_SOLG
Tags:exe lockbit lockbit black Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'158
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Searching for the window
Gathering data
Malware family:
LockBit Ransomware
Verdict:
Malicious
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
64 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Ransomware.Lockbit
Status:
Malicious
First seen:
2022-07-12 14:43:33 UTC
File Type:
PE (Exe)
AV detection:
23 of 26 (88.46%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
f9b9d45339db9164a3861bf61758b7f41e6bcfb5bc93404e296e2918e52ccc10
MD5 hash:
7fb11398c5be61445bee1efa7c9caa31
SHA1 hash:
ced1c9fabfe7e187dd809e77c9ca28ea2e165fa8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:LockbitBlack_Loader
Author:Zander Work
Description:Hunting rule for the Lockbit Black loader, based on https://twitter.com/vxunderground/status/1543661557883740161
Rule name:LockbitBlack_Loader_Rule
Author:Luis Fabuel
Description:Hunting rule for the Lockbit Black loader, based on https://twitter.com/vxunderground/status/1543661557883740161
Rule name:RANSOM_Lockbit_Black_Packer
Author:SECUINFRA Falcon Team
Description:Detects the packer used by Lockbit Black (Version 3)
Reference:https://twitter.com/vxunderground/status/1543661557883740161
Rule name:V3_Lockbit_Black_Packer
Author:Luis F.R
Description:Detects the packer used by Lockbit Black (Version 3)
Reference:https://twitter.com/vxunderground/status/1543661557883740161

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments