Ransom

Ransom:Win32/Lockbit.STB malicious file

Malware Removal

The Ransom:Win32/Lockbit.STB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Lockbit.STB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Exhibits possible ransomware file modification behavior
  • Attempts to disable Windows Defender
  • Anomalous binary characteristics

How to determine Ransom:Win32/Lockbit.STB?


File Info:

name: 03B14473EEF5B7E38D9A.mlw
path: /opt/CAPEv2/storage/binaries/a56b41a6023f828cccaaef470874571d169fdb8f683a75edd430fbd31a2c3f6e
crc32: D79BBD4E
md5: 03b14473eef5b7e38d9a5041c1af0a76
sha1: 371353e9564c58ae4722a03205ac84ab34383d8c
sha256: a56b41a6023f828cccaaef470874571d169fdb8f683a75edd430fbd31a2c3f6e
sha512: eb39446791d4cdbfcd13dfc3ee1902cbc80f946d177e53a2927ef1e53257113e904ae5b5711a5622769b45bfcb961cd9c33158ad9c1f5e1258ff91d8bc753615
ssdeep: 3072:o5uyulsHwDV1gFnTwn7zwJGJ+ut5kCI5Gzei3N2VzRmK:o5uZ1DPgFnk7EJwZI5gDN2VVm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165F36C227112D177C4A239F1B32A76A1B39D8E2C16A8A453FAF8DF0538778237F15947
sha3_384: 678b1c28bd8049e637192e8359173e252ea8e7f9f05fdd0667268497ce1e4b4d986fe5afa5dd2eb65096d004c56e11a4
ep_bytes: 900f1f840000000000e883fbffff0f1f
timestamp: 2022-06-27 14:55:54

Version Info:

0: [No Data]

Ransom:Win32/Lockbit.STB also known as:

BkavW32.AIDetect.malware1
ElasticWindows.Ransomware.Lockbit
MicroWorld-eScanTrojan.GenericKD.61021889
FireEyeGeneric.mg.03b14473eef5b7e3
CAT-QuickHealRansom.Lockbit3.S28401281
ALYacTrojan.Ransom.LockBit
CylanceUnsafe
VIPRETrojan.GenericKD.61021889
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00589e951 )
BitDefenderTrojan.GenericKD.61021889
K7GWTrojan ( 00589e951 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Genus.LHX
CyrenW32/ABRisk.KQVI-5753
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32Win32/Filecoder.BlackMatter.E
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Lockbit.aq
AlibabaRansom:Win32/Lockbit.2b9c59d9
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Lazy.165888.A
RisingTrojan.Generic@AI.94 (RDML:gUX0SyjmPjQi6kVmvPn+iA)
Ad-AwareTrojan.GenericKD.61021889
SophosMal/Generic-S + Troj/Lockbit-F
ComodoMalware@#7iufhsftddh7
DrWebTrojan.PWS.Siggen3.19271
ZillyaTrojan.Encoder.Win32.3076
TrendMicroRansom.Win32.LOCKBIT.YXCGFT
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.61021889 (B)
IkarusTrojan-Ransom.BlackMatter
JiangminTrojan.Encoder.auh
WebrootW32.Ransom.Lockbit
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.720E
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Lockbit.STB
GDataTrojan.GenericKD.61021889
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.LockBit.C5191980
McAfeeRDN/Ransom
MAXmalware (ai score=100)
VBA32TrojanRansom.BlackMatter
MalwarebytesRansom.LockBit
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.LOCKBIT.YXCGFT
TencentMalware.Win32.Gencirc.11fd9259
YandexTrojan.Encoder!3PYRZMzYLQI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.185525898.susgen
FortinetW32/Filecoder_BlackMatter.E!tr.ransom
BitDefenderThetaAI:Packer.6B017F231E
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]

How to remove Ransom:Win32/Lockbit.STB?

Ransom:Win32/Lockbit.STB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment