PULSE NAME
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
WHITE AlienVault 2025-01-27 Modified: 2025-01-27
62
IOCs
HIGH VOLUME
This report details an intrusion that began with the execution of a Cobalt Strike beacon masquerading as a Windows Media Configuration Utility. The threat actor used various tools for persistence, lateral movement, and data exfiltration, including SystemBC and GhostSOCKS proxies, Rclone, and PsExec. They conducted extensive reconnaissance and credential harvesting across multiple systems. After 11 days, they deployed LockBit ransomware using a combination of WMI and PsExec. The attack involved disabling Windows Defender, leveraging scheduled tasks, and exploiting legitimate processes. The threat actor exfiltrated data to MEGA.io and an FTP server before encrypting the environment.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Cobalt Strike - S0154 SystemBC GhostSOCKS LockBit
Indicators of Compromise (22 / 62 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 03af38505cee81b9d6ecd8c1fd896e0e 2025-01-27
FileHash-MD5 0aa05ebc3b6667954898cfccc4057600 2025-01-27
FileHash-MD5 0f7b6bb3a239cf7a668a8625e6332639 2025-01-27
FileHash-MD5 2800a10c4afae44978d906b2abaed745 2025-01-27
FileHash-MD5 303951d4c50efb2e991652225a6f02b1 2025-01-27
FileHash-MD5 40852fde665eb9119fcc565bd68de680 2025-01-27
FileHash-MD5 4457256150386acec794e9e8ee412691 2025-01-27
FileHash-MD5 4794accd22271a28547fb3613ee79218 2025-01-27
FileHash-MD5 573a213191985c555dd7e8de5f0a9cae 2025-01-27
FileHash-MD5 57f791f7477b1f7a1b3605465d054db8 2025-01-27
FileHash-MD5 6505b488d0c7f3eaee66e3db103d7b05 2025-01-27
FileHash-MD5 671b967eb2bc04a0cd892ca225eb5034 2025-01-27
FileHash-MD5 6d44c5fb49258f285769e50830fc59af 2025-01-27
FileHash-MD5 6e91c474d90546845b1f3f9e7a33411a 2025-01-27
FileHash-MD5 71c8c1a0056fd084bc32a03d9245ad10 2025-01-27
FileHash-MD5 8ed408107f89c53261bf74e58517bc76 2025-01-27
FileHash-MD5 90f9044cfee2c678fe51abd098bdfe97 2025-01-27
FileHash-MD5 996ad32c7ae2190b7fa7876df0d7b717 2025-01-27
FileHash-MD5 a0e9f5d64349fb13191bc781f81f42e1 2025-01-27
FileHash-MD5 b254f8f03e61bd9469df66c189d79871 2025-01-27
FileHash-MD5 d9adb3dd6df169e824b2867a2b8cba89 2025-01-27
FileHash-MD5 ea327ed0a3243847f7cd87661e22e1de 2025-01-27