s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.lokibot

📛 Threat Title

Malware family: LokiBot

Category: LokiBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.lokibot`. Printable name: LokiBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.lokibot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.lokibot

IOC database

Type
domain
Value
apk.lokibot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.lokibot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.lokibot

References (1)

Remediations (10)

  • web:any.run

    LokiBot malware analysis An analysis session displaying the simulation of the contamination process created by the ANY.RUN interactive malware hunting service provides the perfect opportunity for malware analysis to see how the contamination process unfolds on an infected machine.

  • web:bazaar.abuse.ch

    Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Lokibot .

  • web:cybersecuritynews.com

    The Steganographic Embedding Mechanism Understanding how the malware hides code within image files reveals the technical sophistication of this attack. The .NET loader contains embedded PNG and BMP files within its resource section. These image files have been specifically crafted to contain the Lokibot payload encoded across multiple pixel values.

  • web:github.com

    About End to end malware analysis of LokiBot using Ghidra, x64dbg, Volatility, and FlareVM with actionable remediation guidance

  • web:malpedia.caad.fkie.fraunhofer.de

    2021-06-08 ⋅ ilbaroni LOKIBOT - A commodity malware Loki Password Stealer (PWS) 2021-04-06 ⋅ InfoSec Handlers Diary Blog ⋅ Jan Kopriva Malspam with Lokibot vs. Outlook and RFCs Loki Password Stealer (PWS)

  • web:www.aha.org

    What follows is an update to the previous HC3 analysis of LokiBot , a timeline of multi-sector targeted applications, detection strategies, sample MITRE ATT&CK techniques, indicators of compromise, and recommended defenses and mitigations against the malware .

  • web:www.cisa.gov

    LokiBot uses a credential- and information-stealing malware , often sent as a malicious attachment and known for being simple, yet effective, making it an attractive tool for a broad range of cyber actors across a wide variety of data compromise use cases.

  • web:www.hhs.gov

    For example, the backdoor functionality built into LokiBot could allow an attacker to remotely control an infected system and use it to download additional malware . After using LokiBot to gain initial access to a system, an attacker could download ransomware or other malware to expand their capabilities and the impact of their attack.

  • web:www.hipaajournal.com

    HHS Issues Warning Issued About LokiBot Malware Posted By Steve Alder on Oct 4, 2023 The Health Sector Cybersecurity Coordination Center (hC3) has published an Analyst Note about LokiBot - one of the most prevalent and persistent malware families. LokiBot , aka Loki PWS, has been used in attacks on a variety of industry sectors over the past 8 years, including critical infrastructure ...

  • web:www.splunk.com

    An analysis on the updated .NET steganography loader delivering Lokibot malware , including evasion techniques, MITRE ATT&CK TTPs, and Splunk detections to enhance threat identification.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.