惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Docker
N
Netflix TechBlog - Medium
罗磊的独立博客
F
Full Disclosure
I
InfoQ
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The Register - Security
The Register - Security
The GitHub Blog
The GitHub Blog
U
Unit 42
Microsoft Security Blog
Microsoft Security Blog
Webroot Blog
Webroot Blog
Apple Machine Learning Research
Apple Machine Learning Research
T
Threatpost
博客园 - 【当耐特】
C
Cybersecurity and Infrastructure Security Agency CISA
P
Privacy International News Feed
Simon Willison's Weblog
Simon Willison's Weblog
T
Threat Research - Cisco Blogs
Y
Y Combinator Blog
P
Proofpoint News Feed
B
Blog RSS Feed
G
GRAHAM CLULEY
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cisco Talos Blog
Cisco Talos Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
P
Privacy & Cybersecurity Law Blog
Know Your Adversary
Know Your Adversary
I
Intezer
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
L
LangChain Blog
B
Blog
雷峰网
雷峰网
K
Kaspersky official blog
S
Secure Thoughts
Security Latest
Security Latest
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Security @ Cisco Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

Jerome Segura – ThreatDown by Malwarebytes

WorkersDevBackdoor and MadMxShell converge in malvertising campaigns SmartApeSG walkthrough ClearFake walkthrough - ThreatDown by Malwarebytes Gootloader walkthrough - ThreatDown by Malwarebytes Threat actors ride the hype for newly released Arc browser - ThreatDown by Malwarebytes A peek inside a malvertising campaign - ThreatDown by Malwarebytes FakeBat - ThreatDown by Malwarebytes Nitrogen - ThreatDown by Malwarebytes Corporate users targeted via malicious ads and modals - ThreatDown by Malwarebytes
LockBit Black - ThreatDown by Malwarebytes
Jerome Segura · 2024-05-02 · via Jerome Segura – ThreatDown by Malwarebytes
CISA ransomware notification

LockBit Black via zipped attachment in email

LockBit Black, tested on May 1, 2024

Today we are looking at a ransomware attack that originated from a malicious email. This is a typical social-engineering attack that could target any of your employees, and perhaps would be most effective against those who regularly communicate with third parties. The lure here is a Document, but it could very well be more specific, such as an invoice, a parking ticket, etc.

This email is from a malspam campaign that was observed around the end of April 2024 initiated by a ransomware affiliated with LockBit Black (AKA LockBit 3.0).

Distribution (email->ZIP->SCR->download EXE)

This LockBit Black malware sample was distributed via a malspam campaign using the Phorpiex botnet. The email with subject “Your Document” contains a zipped attachment. The file inside the archive uses the double extension trick (.doc.scr) to mimic a Word document.

Wallpaper change:

Encrypted documents:

Ransom note:

        !! ALL YOUR FILES ARE ENCRYPTED !!!

        You can't restore them without our decryptor.

        Don't try to use any public tools, you could damage the files and lose them forever.

        To make sure our decryptor works, contact us and decrypt one file for free.

        Download TOX messenger: https://tox[.]chat/

        Add friend in TOX, ID: {sanitized}

Process flow

Protection

We tested ThreatDown by looking at each protection layer:

  • Anti-Exploit: attachment blocked when opened from email client
  • Anti-Malware engine: attachment detected when executed from disk
  • Anti-Malware engine: LockBit payload when executed from disk
  • Anti-Ransomware: Lockbit encryption

Endpoint Detection and Response (EDR)

EDR detected suspicious activity related to LockBit disabling volume shadow copies.

Mitigations

ThreatDown customers were already protected against this threat, and not just via one specific security layer. This is especially important for threats like ransomware because they are very destructive by nature.

There were a few elements in this attack that anyone can learn from:

  • The malicious email was asking the user to “reply as soon as possible”. This is a common tactic used by criminals because they know that they often have a very limited time window before their payload is being detected. They want you to do something quickly and let your guards down.
  • The attachment, a zip file, contained an executable. Many, if not most email clients do not allow executables to be attached directly as is. Threat actors will compress them as .zip, .rar or some other extension. There are of course legitimate archives, but you should be extra careful when a file is packaged that way.
  • The file inside the zip was named Document.doc.scr. The thing is, Microsoft Windows will often omit known extension types. Because of that, the file will look like it has a .doc extension (and therefore seems like a document) whereas it is in fact a .scr (screensaver, but executable). It is a good idea to change that setting and force Windows to show you all extensions.

Did you like this walkthough? For more, check out our index page here.

Indicators of Compromise (IOCs)

Email subject

Your Document

Email body

Hello, you can find your document in the attachment.

Please reply as soon as possible.

Kind regards, GSD Support.

Attachment name

Document.zip

Attachment SHA256

1c5fd7bf511885054464124142f793501ab2c6e987b203c1a5f4b3bdcccb1fa1

Extracted attachment name

Document.doc.scr

Extracted attachment SHA256

0cc54ffd005b4d3d048e72f6d66bcc1ac5a7a511ab9ecf59dc1d2ece72c69e85

LockBit download URL

hxxp[://]193[.]233[.]132[.]177/lbb[.]exe

LockBit SHA256

a18a6bacc0d8b1dd4544cdf1e178a98a36b575b5be8b307c27c65455b1307616