| File name: | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe |
| Full analysis: | https://app.any.run/tasks/4c618300-5deb-4cac-b4eb-0f1707207655 |
| Verdict: | Malicious activity |
| Threats: | LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations. |
| Analysis date: | May 15, 2025, 17:21:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | ABB148AFDB78E76007D59ED015E6BADE |
| SHA1: | 9D469A6DB4899247188C4832FF20B7FB84516300 |
| SHA256: | 5988E75518B2F365671DC49DA18B5A70274351721F1F3A8F8F7BF32984E4024C |
| SSDEEP: | 3072:TknnYP1Z0vx1tN/llwQBTbp8StBur8bAo5dlE4zBgAgZkZz0Luc:eZBTNZBVdc |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:04:29 05:58:36+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 124416 |
| InitializedDataSize: | 34816 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x19840 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 660 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 660 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1052 | bcdedit /set {default} recoveryenabled No | C:\Windows\System32\bcdedit.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1072 | C:\WINDOWS\System32\vdsldr.exe -Embedding | C:\Windows\System32\vdsldr.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Virtual Disk Service Loader Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1228 | /c wevtutil cl application | C:\Windows\System32\cmd.exe | — | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1452 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1660 | /c bcdedit /set {default} recoveryenabled No | C:\Windows\System32\cmd.exe | — | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1660 | /c wevtutil cl security | C:\Windows\System32\cmd.exe | — | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1672 | wevtutil cl security | C:\Windows\System32\wevtutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Eventing Command Line Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1676 | wbadmin DELETE SYSTEMSTATEBACKUP -deleteOldest | C:\Windows\System32\wbadmin.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Command Line Interface for Microsoft® BLB Backup Exit code: 4294967293 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | XO1XADpO01 |
Value: "C:\Users\admin\AppData\Local\Temp\5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe" | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LockBit |
| Operation: | write | Name: | full |
Value: 863D80A034C782307A1760342A53270398CF8DB15D7A2EDEA61D813A724D9F6ADF2762977D1050E896F146017E51D63F0BCF1A90BAA27401D3933957A800D77ACA97D8E1C5083CE545B95354092ACCC3BBEE675E2CF8F4B42FCEA6473CBB862F001926A9EF8E5224CB72F767DDAFDAD746EBC75E097B89E1DED7D92FFD732FB255876AABD3A5BA90E628C23622DC903E8FA7EE93CDFF1F4AF0B7DD6301397E92EE8E444D7103AFA68F924911623B40A54BFA04A79D5A9E186BE1CD922490A8840387102A9C0E9F798AB9564FC5FBE2BE46CBA15FAAD7D9FAF632CCB257B7651DD47F2D26154359963303A21DCB26CD52065E30055AC86B497E83E07D3E4D3C540AC81223E75E953ED8FF9217096415911E78AD95071D9FAB220013C4F10765A479429B22B501E18325E351D41E5CC24FE021ACA63B4BE33EDFF7DD14A2546AF8E0C1658C5072E26F79F1DF1EBD552AA4BC3AFD47A9F355802A05065089165A952BFBFCF527F05442E28D9685ACC24412752B48BDF1A42EC7AF0069160B61F2C674239A8953C7BD5FE404F9BCA7FCDFB035EE9D34F777A5B15A75E582316935756C342E2989A090C0481C476AB26631485681399D3878F7F31B726A765894647394CE1C4B26C21400CC35BB07DC4F051E166474686B4F3809CF5C48C3D6B1CA17CF0CB3DCD0ADCAC142980C68DF8D253EA503A6504FC964902B3E7D07DD2D047D0F82D0DF913D9F5FFC362A131A116BACDD2179A0E8923C3E172B5D811973B383B0F439EEADB45929E8DA4ECD5463733E5AA7F7ACF792BFDAAE8FF2A604CCD5EF1A48402A365F60FDACDDD381234E55E70CB9000E890C2A5845D07BE5457AD52823C9739B5F5CEF3BD2E3E6582D7E1BA5BC6B81C7F5DDB1CF399597AC5EB84C190F710FE915B6EEB66BADF76DAADDBA5D4AFE3849DFE805D1F6CB96F3F072263B82B309A8FDCD4EBBB9CEF428A5E71BE176B7D136FC4369351E60345632EB58BBB3B9F9D93C6375FC2A7D23A0AF3B05B1CEE1C6F012CC3972DCF98996C06D3226161B24A14536C2BAE0AC1C1576B9136230AC1B1862A597120DE531E29C31CE343BFF29CED04055D967EB853C14911013C5C4073AC2920E20C83C513A5CD9F08F50F5F6C698BB64D84F3633A2E115988F6F240B92514D8CA9A379506466CCBA53E49DB99DD69229B92CAC7FA652933E456B59A8F11AB5E58A780ABF8755BFCB8324CA2B9F1B53D8F277FB5EFD5586C17D144F67A6A21FC171104CB2C81A57B7DEF19609230FDADAB45D08FFFA48373A78188BACB907978B0AC48190F4B11F42D1268606BCF12214374A43825093C22632E082DE3EB2278E2E1234CCA6745A8449CDAC4C9E6890F0DD9D893813BFBE96F1086E1C9E526B9EE3848E5BB47A6B4D65FBBC69FF69E6740D114A45EB41C7E3371F9180132EC6987C91D926B369E9874987F773BEB58357FE0C9F9179FF56C1A3E2A02F00BF74DBA38B7AB04A9C786E8AF9AE62F881F29B29EB773AC54E7805186BED473F09C2673B8932B4486B1FDF84B3B607F581E3E0B8A1840E4D1825EF754F412E9904A15B18AC40F5BD859A90E020361F2A61945DCEBFE132A7CFE76CDD7E164EE8C91DCB9EB2BB0A5A6323D9794A25824D6234E6288A194672DA58736AB45C0C8548F9EF88804B6DBF5624B32CCFAE195B17848E5DCED174DFEAEF4AD9B208A800DF777B2523A44F2F77AE21EF663F5B68A36FA5A63B6DAB71B64AA5B0EFAFE75BAA2A92611A953C694CE7EF185913EC619BF265D54F55075E103666305D1C86B83F878BD5ADCB72FD186196CE | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\LockBit |
| Operation: | write | Name: | Public |
Value: 94D1D2A382C47D8067DFB003D300D44EAE1132D1338E083E9701348D4651002C02ACAB5B04266C3FE3A453ECCD741A0D1276694F0FE10D82BF54FE6D19D82132217A0223DA1DCFB43887ED658C5094D7BA6160B6418B749D90774260E128E6BC695DE84AFA9CF408614B61E8AF1A9FE9B01D27C3D0C7A5640CD1B8DBA63C34EDE4AD887A5004A60DF09D23CDE8FE5F242109EA769D888D7EE1B7036796B654E02CF4C31B9F53B7B958B0564E22B9D1341EE25A6A93CE94AA4D5D08A687C11B27848B7E22CEB3E77BA665DD534A63D1BB074DF6D34AAD7219BA50D1617D861BF47A1B1CF67EB31AE8BE5D4D924ADD3B7B3AF43ED63D1BD77E4D4E5CBD8F5A918F010001 | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e73-85a9-11eb-90a8-9a9b76358421} |
| Operation: | write | Name: | MaxCapacity |
Value: 83 | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{eaf65672-68c3-4f99-8d5c-104b5f4d8fff} |
| Operation: | write | Name: | MaxCapacity |
Value: 51 | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e71-85a9-11eb-90a8-9a9b76358421} |
| Operation: | write | Name: | MaxCapacity |
Value: 49 | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e73-85a9-11eb-90a8-9a9b76358421} |
| Operation: | write | Name: | NukeOnDelete |
Value: 0 | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{eaf65672-68c3-4f99-8d5c-104b5f4d8fff} |
| Operation: | write | Name: | NukeOnDelete |
Value: 0 | |||
| (PID) Process: | (7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e71-85a9-11eb-90a8-9a9b76358421} |
| Operation: | write | Name: | NukeOnDelete |
Value: 0 | |||
| (PID) Process: | (7456) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration |
| Operation: | write | Name: | DisplayCalibrator |
Value: C:\Users\admin\AppData\Local\Temp\5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | \\?\Volume{eaf65672-68c3-4f99-8d5c-104b5f4d8fff}\$WINRE_BACKUP_PARTITION.MARKER.lockbit | — | |
MD5:— | SHA256:— | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | \\?\Volume{2f5c5e71-85a9-11eb-90a8-9a9b76358421}\NvVars.lockbit | binary | |
MD5:1B6D8F02332E50665E5F3EBEC68915BF | SHA256:EC144DD3FD496037D3BA6EBE798246B974FA1E228EE2DA4A175CC9CD75C18565 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | C:\found.000\dir0000.chk\UpdateSessionOrchestration.048.etl.lockbit | binary | |
MD5:B14B352B6D8E53F330F4004256907629 | SHA256:1261DDC68472BC4B4634AB432D4406C47D47065C53BBBE6EBC3B2DA13B9BC475 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | C:\found.000\dir0000.chk\UpdateSessionOrchestration.016.etl.lockbit | binary | |
MD5:A3BC67DC29FC491624143846C7F2B212 | SHA256:ADD1BF1B78F3B8B0F259864E6CE16412AA91BFB57A0F8C6821DD61461952D6C1 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | C:\$WinREAgent\Backup\location.txt.lockbit | text | |
MD5:F09B8CA2E0F41BA2270F6EF5062BB1A8 | SHA256:E4C22462C0619D55326E12995176E7A5D14C16E1F6791F0F8C7E55034AAB1D35 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | C:\$WinREAgent\Rollback.xml.lockbit | text | |
MD5:DD7327DF2C5DFA8E5FCD520169E98059 | SHA256:68B961E182957866BD6BBFB92AAF163FFD7D9AF40765CE0D390E5EF9F8C0E794 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | C:\found.000\dir0000.chk\UpdateSessionOrchestration.058.etl.lockbit | binary | |
MD5:389F45A91E7FFC038CCCDB460AAD253D | SHA256:7C38AD8787A332AB2026A1C7516B5502842F8946E1D706ACCB9523BF6210F639 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | \\?\Volume{2f5c5e73-85a9-11eb-90a8-9a9b76358421}\$RECYCLE.BIN\S-1-5-21-1693682860-607145093-2874071422-1001\desktop.ini | ini | |
MD5:AD0B0B4416F06AF436328A3C12DC491B | SHA256:23521DE51CA1DB2BC7B18E41DE7693542235284667BF85F6C31902547A947416 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | \\?\Volume{2f5c5e71-85a9-11eb-90a8-9a9b76358421}\$RECYCLE.BIN\desktop.ini | ini | |
MD5:AD0B0B4416F06AF436328A3C12DC491B | SHA256:23521DE51CA1DB2BC7B18E41DE7693542235284667BF85F6C31902547A947416 | |||
| 7584 | 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe | C:\found.000\file00000005.chk.lockbit | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8448 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
8448 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.168.124:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 2.16.168.124:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
— | — | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |