Managed XDR

lbgame.zip (Lockbit) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
lbgame.zip
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
553 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
66df25301655b82c7d636944cc0146c37326e599
SHA256
10106eb0ac3f71d67c6c5f758bfcc82eac132f9ad1cbbb25c8472c0aa4802cf8
MD5
bd1a5c6e90991f361736b5832cd2f819

Вредоносное ПО

  • Lockbit

Сигнатуры

Defense Evasion

T1036.001 invalid_authenticode: Digital signature of the executable file has failed the verification
T1027.002 unnamed_memory_regions_contains_pe: One or several unnamed memory regions are PE files
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data

Impact

T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)

Other

lockbit: Detected ransomware Lockbit
static_pe_anomaly: The PE file structure contains anomalies
only_exec_in_archive: The archive contains only an executable file
require_administrator: Requests administrator privileges
suspicious_network_port: Performs TCP or UDP request to non-standard port
pe_overlay: PE file contains overlay

Похожие отчёты