Managed XDR

home-petik-ss-malware-...poet-rat_sliver_snatch (Lockbit) — malware analysis report

File info

Filename
home-petik-ss-malware-2025-06-17_545b4cd7e20837fc68ce194f6c63ba76_cobalt-strike_frostygoop_luca-stealer_poet-rat_sliver_snatch
File type
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
File size
2.1 MB
First seen
Last seen

Environment

win7/x64 en

Hashes

SHA1
b157c07b86cc19c59ac3a7ca953b2ef2bf0f74ea
SHA256
98679311bc3268729dd2b060432f042ac3f5194cc486c61ded80c4c9b58019ba
MD5
545b4cd7e20837fc68ce194f6c63ba76

Malwares

  • Lockbit

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Impact

T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1489 stops_service: Stops Windows services
T1490 disables_system_restore: Disables System Restore

Other

lockbit: Detected ransomware Lockbit
ransomware_shadowcopy: Removes volume shadow copies
test_check_service: Starts services

Related reports