TF-MAL-apk.lokibot
📛 Threat Title
Malware family: LokiBot
Description
ThreatFox malware family `apk.lokibot`. Printable name: LokiBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.lokibot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.lokibot
IOC database
- Type
- domain
- Value
apk.lokibot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.lokibot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.lokibot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
LokiBot malware analysis An analysis session displaying the simulation of the contamination process created by the ANY.RUN interactive malware hunting service provides the perfect opportunity for malware analysis to see how the contamination process unfolds on an infected machine.
-
web:bazaar.abuse.ch
Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with Lokibot .
-
web:cybersecuritynews.com
The Steganographic Embedding Mechanism Understanding how the malware hides code within image files reveals the technical sophistication of this attack. The .NET loader contains embedded PNG and BMP files within its resource section. These image files have been specifically crafted to contain the Lokibot payload encoded across multiple pixel values.
-
web:github.com
About End to end malware analysis of LokiBot using Ghidra, x64dbg, Volatility, and FlareVM with actionable remediation guidance
-
web:malpedia.caad.fkie.fraunhofer.de
2021-06-08 ⋅ ilbaroni LOKIBOT - A commodity malware Loki Password Stealer (PWS) 2021-04-06 ⋅ InfoSec Handlers Diary Blog ⋅ Jan Kopriva Malspam with Lokibot vs. Outlook and RFCs Loki Password Stealer (PWS)
-
web:www.aha.org
What follows is an update to the previous HC3 analysis of LokiBot , a timeline of multi-sector targeted applications, detection strategies, sample MITRE ATT&CK techniques, indicators of compromise, and recommended defenses and mitigations against the malware .
-
web:www.cisa.gov
LokiBot uses a credential- and information-stealing malware , often sent as a malicious attachment and known for being simple, yet effective, making it an attractive tool for a broad range of cyber actors across a wide variety of data compromise use cases.
-
web:www.hhs.gov
For example, the backdoor functionality built into LokiBot could allow an attacker to remotely control an infected system and use it to download additional malware . After using LokiBot to gain initial access to a system, an attacker could download ransomware or other malware to expand their capabilities and the impact of their attack.
-
web:www.hipaajournal.com
HHS Issues Warning Issued About LokiBot Malware Posted By Steve Alder on Oct 4, 2023 The Health Sector Cybersecurity Coordination Center (hC3) has published an Analyst Note about LokiBot - one of the most prevalent and persistent malware families. LokiBot , aka Loki PWS, has been used in attacks on a variety of industry sectors over the past 8 years, including critical infrastructure ...
-
web:www.splunk.com
An analysis on the updated .NET steganography loader delivering Lokibot malware , including evasion techniques, MITRE ATT&CK TTPs, and Splunk detections to enhance threat identification.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.