MALICIOUS — 402a43da48d05ab4eeb3df95ed2abaeffce6f82782150daed5afed792b7ede6d_unpacked_diag
MALICIOUS — 402a43da48d05ab4eeb3df95ed2abaeffce6f82782150daed5afed792b7ede6d_unpacked_diag is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (79/100), attributed to the LockBit family. 3 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
402a43da48d05ab4eeb3df95ed2abaeffce6f82782150daed5afed792b7ede6d - SHA-1:
c5ad0515831b3d3856a2fa6c0c654a904f69a068 - MD5:
bc6944356410bf5be366f6a1d13f9d47 - imphash:
521eeded47f0ce98ecf1feb3331268d7 - ssdeep:
1536:TbCI2ojymobrUftNrVkwxpXvuSkAhZKCMWKpmT9aUpFFXbWyaurf0D:TvdemobruTkwxpXtROfpmEgFFrrauw - TLSH:
T15A3A3CAA401A2351CAF5ED64D8188CED4021B49C7471BB6D4E0FC22E54F61FBD9FE892 - Submitted as: 402a43da48d05ab4eeb3df95ed2abaeffce6f82782150daed5afed792b7ede6d_unpacked_diag
- File type: pe · Size: 99840 bytes
- Verdict: malicious (79/100) · Family: LockBit
Detections (3 of 53 engines)
- Microsoft Defender: Ransom:Win32/LockBit.PA!MTB
- Emsisoft (Emergency Kit): Generic.Dacic.17937.3B493AEB
- Kaspersky (KVRT): UDS:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 79/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Ransom:Win32/LockBit.PA!MTB (rule
Ransom:Win32/LockBit.PA!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.17937.3B493AEB (rule
Generic.Dacic.17937.3B493AEB) - engine signal, weight 0.55, confidence 0.85 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- C:\hopelL
- C:\hopelH
- C:\diskpart_scrub.txt
- C:\Windows\Minidump
- C:\Windows\LiveKernelReports
- C:\Windows\Temp
- C:\Windows\Prefetch
- C:\Windows\SoftwareDistribution
- C:\Windows.old
- C:\Windows\System32\hopeless_v52.exe
- C:\hopeless_v52.exe
- C:\pagefile.sys
- C:\hiberfil.sys
- C:\swapfile.sys
- C:\Windows\System32\cmd.exe
- C:\HOPELESS_README.txt
- C:\ProgramData\Microsoft\Windows
- S:\EFI
- C:\System
- C:\Users\
- C:\Windows\System32\drivers\etc\
More LockBit samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report