Managed XDR

9d0d2d80acdfb3e652b2530c878563a3.virus (Lorenz) — malware analysis report

File info

Filename
9d0d2d80acdfb3e652b2530c878563a3.virus
File type
PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
File size
1.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
3c3b25bfdde6ca1190be3611c745a0531ce88bdd
SHA256
5220ed12a1b8d1ca53a7b15fe3c57905bbd5851a26cf5b3a7a05d55176555ad9
MD5
9d0d2d80acdfb3e652b2530c878563a3

Malwares

  • Lorenz

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_upx: The executable file is compressed using UPX
T1027.002 pe_features: Executable file has PE anomalies (may be false positive)
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1033 recon_beacon: The process has sent information about the computer over the network
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1497.001 antivm_queries_computername: Retrieves the computer name

Command and Control

T1071.001 recon_beacon: The process has sent information about the computer over the network
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Impact

T1486 modifies_files: Cryptolocker indicators detected (renamed 100 or more files)
T1486 ransomware_extensions: Ransomware(s) Lorenz indicators detected (specific extension is added to files)
T1486 mass_data_encryption: Encrypts data using the same key (possible ransomware behaviour)
T1485 deletes_files: Removes 100 or more files from C: drive

Other

yara_rules: Static rules
ce_info: Lorenz Configuration Data found
lorenz: Detected Lorenz ransomware
creates_in_windows: Creates files in the Windows directory
cryptolocker_wallpaper: Ransomware indicators detected (changes the desktop wallpaper file)
dead_host: Connects to IP addresses that do not respond to requests
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
writes_data: Writes big amount of data to disk

Related reports