Updated 2026-10-08 14:41:26 +00:00
Leaked lockbit 3 iso good for archive reasons and analysis
Updated 2026-10-08 05:38:24 +00:00
Windows .NET remote-access trojan (RAT) with an enabled keylogger.
Configured callback: retrac.ethanremote.co.uk, TCP port 300. Uses encrypted messages and automatic reconnection.
Installs a hidden copy at %APPDATA%\SubDir\subDirsystem.exe and attempts persistence through a startup entry named SecurityHealthsrane. Records keystrokes and active window titles, storing logs under %APPDATA%\Logs.
Remote capabilities include screen viewing, mouse/keyboard control, webcam and microphone capture, file upload/download/deletion, shell commands, process and registry management, reverse proxying, and downloading/running additional programs.
Additional code attempts administrator elevation, Defender exclusions, and blocking security websites through the Windows hosts file. These actions are conditional; some routines occur after the connection loop.
Incomplete features in this sample: stored-password retrieval returns an empty list, and the rootkit download URL is a placeholder.
Findings are based on static analysis of Update.exe. The executable was not run, and control-server availability was not checked.
Updated 2026-10-07 19:51:36 +00:00
Updated 2026-10-07 19:28:01 +00:00
Updated 2026-10-07 19:28:00 +00:00
Updated 2026-10-07 19:27:59 +00:00
Updated 2026-10-07 19:27:58 +00:00
Updated 2026-10-07 19:27:57 +00:00
Updated 2026-10-07 19:27:57 +00:00
Static analysis and source evidence from 5mb8dr6.rar: Invoked/Quasar client, plugins, and loader.
Updated 2026-10-02 09:27:51 +00:00
Static analysis and recovered code: RAR, atlasb.bat, PowerShell/Donut, and the matching u.exe payload.
Updated 2026-10-02 09:27:15 +00:00