Managed XDR

vtdl_1787557044_k7oz3jo7 (BlackMatter, Lockbit) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_1787557044_k7oz3jo7
Тип файла
PE32 executable (GUI) Intel 80386, for MS Windows
Размер файла
151 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
88cf5ca0900e6e0614dc7a6abb71edfa2245a0b9
SHA256
ec0cf34d9f46f222463c6ba43f61f2230537e0a646694dea33d0894d3421e330
MD5
f66f85e214185d3e273d64d11103cfe3

Вредоносное ПО

  • BlackMatter
  • Lockbit

Сигнатуры

Persistence

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key

Privilege Escalation

T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1562.001 disables_security: Disables Windows Security options
T1574.011 persistence_services: Modifies Services registry key
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1518.001 antiav_detectservice: Attempts to detect installed antiviruses by a certain service
T1518 locates_browser: Attempts to identify where browsers are installed

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Impact

T1489 stops_service: Stops Windows services
T1489 service_control_stop: Stops services via ControlService

Other

yara_rules: Static rules
lockbit: Detected ransomware Lockbit
no_graphical_activity: No graphic activity
creates_in_programdata: Creates files in the ProgramData directory
test_check_service: Starts services

Похожие отчёты