Managed XDR

locker.exe (Conti) — malware analysis report

File info

Filename
locker.exe
File type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size
177.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
1a09231725ae107377144b16d3bc45ce78768250
SHA256
e3667cfe612890b19a16c381fbdbe2c2707f1c5d660fe0c1c80a836fa33cd2ec
MD5
0bc0a16de775396555f56ca33d30cbba

Malwares

  • Conti

Signatures

Execution

T1047 has_wmi: Executes one or several WMI requests

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1552 infostealer_mail: Collects personal data from local email clients
T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes
T1083 crawls_directories: Opens a huge number of directories all over disk C: (possibly, searches for sensitive data)
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1016 get_hostname: Attempts to get hostname

Collection

T1114 infostealer_mail: Collects personal data from local email clients

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Impact

T1486 ransomware_files: Ransomware indicators detected Conti (creates keys and the instruction on how to unlock the files)
T1486 ransomware_files_2: Ransomware(s) Conti indicators detected (creates keys and the instruction on how to unlock the files)

Other

yara_rules: Static rules
network_bind: Starts servers listening at None
no_graphical_activity: No graphic activity
create_rpc_bindings: Creates RPC connection
creates_in_programdata: Creates files in the ProgramData directory
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services

Related reports