PULSE NAME
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware
WHITE LockBit Iandriechack 2025-01-27 Modified: 2025-02-26
9
IOCs
LOW VOLUME
The threat actors then established the usage of multiple proxy tools such as SystemBC and GhostSOCKS to maintain persistence and traverse laterally within the environment. Over the course of the next few days, they leveraged a combination of tools: PsExec, WMI, and Rclone. Initial attempts at exfiltration via FTP failed, but the attackers shifted later to MEGA.io using Rclone and succeeded in exfiltrating gigabytes of sensitive information within a 16-hour timeframe. On the eleventh day, LockBit ransomware was released onto all available Windows hosts through batch scripts, scheduled tasks, and administrative tools to maximize their impact. Because of this, data got encrypted to such an extent that it almost paralyzed the operation of the victim.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
LockBit
Indicators of Compromise (9)
All URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://159.100.14.254:443 2025-01-27
URL http://185.236.232.20:445 2025-01-27
URL http://46.21.250.52:21 2025-01-27
URL http://93.115.26.127:21 2025-01-27
URL https://accessservicesonline.com/setup_wm.exe d8b2d883d3b376833fa8e2093e82d0a118ba13b01a2054f8447f57d9fec67030 2025-01-27
domain accessservicesonline.com 2025-01-27
domain compdatasystems.com 2025-01-27
domain retailadvertisingservices.com 2025-01-27
hostname user.compdatasystems.com 2025-01-27