LAPSUS$ is dead, long live HexaLocker?
Common Information
Type Value
UUID 8fd524a9-b0ba-4c84-b9ec-f6ce1612eae2
Fingerprint bf92bd8976e7269c
Analysis status DONE
Considered CTI value 0
Text language
Published Aug. 18, 2024, midnight
Added to db Aug. 31, 2024, 10:44 a.m.
Last updated Nov. 17, 2024, 10:40 p.m.
Headline LAPSUS$ is dead, long live HexaLocker?
Title LAPSUS$ is dead, long live HexaLocker?
Detected Hints/Tags/Attributes 56/2/21
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 414 Last Blog Article https://www.synacktiv.com/en/feed/lastblog.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 707
google.com
Details Domain 1
darkslategray-baboon-853641.hostingersite.com
Details Domain 1
9f905ea7-ebd1-4d49-84f6-ae84e484e49f.zip
Details Domain 4127
github.com
Details File 367
readme.txt
Details File 380
notepad.exe
Details File 1
baloon.sys
Details File 2
netkvm.sys
Details File 1122
svchost.exe
Details File 1260
explorer.exe
Details File 2126
cmd.exe
Details File 1205
index.php
Details File 1
receive.php
Details File 1
9f905ea7-ebd1-4d49-84f6-ae84e484e49f.zip
Details File 1
c:\users\bonjour\desktop\loremipsum.txt
Details Github username 5
synacktiv
Details sha256 1
be759e58413431dbe40d29ea5e399b1ebbfe75847c19a5a8f2610dab9f78ca8b
Details IPv4 1
192.168.122.111
Details Url 1
https://darkslategray-baboon-853641.hostingersite.com/index.php
Details Url 1
https://darkslategray-baboon-853641.hostingersite.com/receive.php
Details Url 1
https://github.com/synacktiv/hexalocker-analysis