Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 15, 2023, 8:47 a.m. | March 15, 2023, 8:49 a.m. |
-
sample2.exe "C:\Users\test22\AppData\Local\Temp\sample2.exe"
2568 -
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | c:\program files (x86)\Google\Chrome\application\chrome.exe |
file | c:\program files\mozilla firefox\firefox.exe |
description | sample2.exe tried to sleep 224 seconds, actually delayed analysis time by 224 seconds |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\{6E5E24E4-E8E8-78AC-0E52-0E6D43D0CFEE} | reg_value | "C:\Users\test22\AppData\Local\Temp\sample2.exe" |
Bkav | W32.AIDetectNet.01 |
Lionic | Trojan.Win32.Generic.4!c |
Elastic | Windows.Ransomware.Lockbit |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.LckbitRnsm.S21641235 |
ALYac | Trojan.Ransom.LockBit |
Zillya | Trojan.Agent.Win32.2362610 |
Sangfor | Ransom.Win32.Lockbit.Vbng |
K7AntiVirus | Trojan ( 0057f63d1 ) |
Alibaba | Ransom:Win32/Lockbit.c99 |
K7GW | Trojan ( 0057f63d1 ) |
CrowdStrike | win/malicious_confidence_100% (W) |
BitDefenderTheta | Gen:NN.ZexaF.36344.7mW@aqwWnog |
VirIT | Ransom.Win32.LockBit.DAM |
Cyren | W32/Ransom.PM.gen!Eldorado |
Symantec | Downloader |
tehtris | Generic.Malware |
ESET-NOD32 | a variant of Win32/Filecoder.Lockbit.E |
APEX | Malicious |
Paloalto | generic.ml |
ClamAV | Win.Trojan.Obfus-43 |
Kaspersky | HEUR:Trojan-Ransom.Win32.Generic |
BitDefender | Gen:Variant.Ransom.Lockbit2.9 |
NANO-Antivirus | Trojan.Win32.Encoder.jtuemz |
ViRobot | Trojan.Win32.Lockbit.982528 |
MicroWorld-eScan | Gen:Variant.Ransom.Lockbit2.9 |
Avast | Win32:LockBit-A [Ransom] |
Rising | Ransom.LockBit!1.D854 (CLASSIC) |
Emsisoft | Gen:Variant.Ransom.Lockbit2.9 (B) |
F-Secure | Trojan.TR/Crypt.XPACK.Gen |
DrWeb | Trojan.Encoder.34248 |
VIPRE | Gen:Variant.Ransom.Lockbit2.9 |
TrendMicro | Ransom.Win32.LOCKBIT.SMYEBGW |
McAfee-GW-Edition | BehavesLike.Win32.Generic.dh |
Trapmine | malicious.high.ml.score |
FireEye | Generic.mg.41687e58130c8bdc |
Sophos | Troj/Lockbit-D |
Ikarus | Trojan-Ransom.LockBit |
GData | Win32.Trojan-Ransom.LockBit.A |
Jiangmin | Trojan.Agent.dltk |
Avira | TR/Crypt.XPACK.Gen |
MAX | malware (ai score=89) |
Antiy-AVL | Trojan/Win32.GenKryptik |
Gridinsoft | Ransom.Win32.LockBit.bot |
Arcabit | Trojan.Ransom.Lockbit2.9 |
ZoneAlarm | HEUR:Trojan-Ransom.Win32.Generic |
Microsoft | Ransom:Win32/Lockbit.STA |
Detected | |
AhnLab-V3 | Ransomware/Win.LockBit.R487041 |
McAfee | Lockbit!41687E58130C |
dead_host | 192.168.56.101:49167 |
dead_host | 192.168.56.1:445 |
dead_host | 192.168.56.1:135 |
dead_host | 192.168.56.101:49166 |