Managed XDR

exemplar (Locky) — malware analysis report

File info

Filename
exemplar
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
575.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
b6eacda7b1910615b803496445e6afea5dd07adb
SHA256
8e731f5f6b50b20fd77699a8b4deb84a9ec03262d56a063e2e083aa081fa81f8
MD5
f111a80e0ff9ef1422d330d2817c9c53

Malwares

  • Locky

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1070.004 deletes_self: Moves to different location or removes the original executable file
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1480 system_default_lang_id_present: Checks the system language
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1070.004 self_removal_command: Executes command to delete itself

Credential Access

T1552.001 infostealer_bitcoin: Attempts to obtain access to Bitcoin/ALTCoin wallets
T1552 cookie_files: Accesses cookie files
T1555.003 cookie_files: Accesses cookie files

Discovery

T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed
T1497.001 antivm_queries_computername: Retrieves the computer name
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1071.001 network_http: Performs HTTP requests
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 100 or more files)
T1486 ransomware_windows_possible: Ransomware indicators detected (possible ransom window creation)
T1486 modifies_files2: Cryptolocker indicators detected (100 or more files are modified)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1486 ransomware_extensions: Ransomware(s) Locky indicators detected (specific extension is added to files)

Other

yara_rules: Static rules
cryptolocker_wallpaper: Ransomware indicators detected (changes the desktop wallpaper file)
unexpected_exception: Unexpected exception
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
writes_data: Writes big amount of data to disk

Related reports