Managed XDR

malware-souk-main-corp...4e296e2918e52ccc10.zip (Lockbit) — malware analysis report

File info

Filename
malware-souk-main-corpus-lockbit-samples-f9b9d45339db9164a3861bf61758b7f41e6bcfb5bc93404e296e2918e52ccc10.zip
File type
Zip archive data, at least v2.0 to extract
File size
160.8 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7811085a49e02218f52bb9750cb898d13b48d118
SHA256
2155a36c5f18297d927ddf8ec1e436932926558b51d33652d5cc77491013dcaf
MD5
affc5c393011cf40e9d3aae86d26e4f4

Malwares

  • Lockbit

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
only_exec_in_archive: The archive contains only an executable file
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity
archive_password_infected: Archive is protected by 'infected' password

Related reports