Managed XDR

commvaultbackup.exe (Lockbit) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
commvaultbackup.exe
Тип файла
PE32+ executable (console) x86-64, for MS Windows
Размер файла
3 MB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
2463f56817746742598596d519833fcd28b9f05a
SHA256
b4e9bffcb6c63c3151cc15a43174afe88c95c1757665374efffd868125a54649
MD5
2a55e32f7c4648d9115e62087b0c1de5

Вредоносное ПО

  • Lockbit

Сигнатуры

Privilege Escalation

T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 opens_process_token: Opens the access token associated with a process

Discovery

T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Collection

T1074.001 access_recyclebin: Manipulation with recyclebin detected

Impact

T1486 modifies_files2: Cryptolocker indicators detected (500 or more files are modified)
T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1490 disables_system_restore: Disables System Restore
T1486 ransomware_extensions: Ransomware(s) Lockbit indicators detected (specific extension is added to files)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies

Other

lockbit: Detected ransomware Lockbit
ransomware_shadowcopy: Removes volume shadow copies
creates_suspended_process: Creates suspended process
test_check_service: Starts services
writes_data: Writes big amount of data to disk

Похожие отчёты

Managed XDR