Managed XDR

dttcodexgigas.812817cf...8cccc4cf4c1c7d7a26e9ee (BlackMatter, Lockbit) — malware analysis report

File info

Filename
dttcodexgigas.812817cf525d8a8eba8cccc4cf4c1c7d7a26e9ee
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
145.5 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
812817cf525d8a8eba8cccc4cf4c1c7d7a26e9ee
SHA256
1af83415135a8329a9295ca6a004a9575aa4a596cf95def3dec9ae7fa3db57cf
MD5
484a8f2a7d735d88308f8477a480267f

Malwares

  • BlackMatter
  • Lockbit

Signatures

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
process_crashed: One of the processes has failed
no_graphical_activity: No graphic activity

Related reports