TF-MAL-py.lokirat
📛 Threat Title
Malware family: Loki RAT
Description
ThreatFox malware family `py.lokirat`. Printable name: Loki RAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.lokirat
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lokirat
IOC database
- Type
- domain
- Value
py.lokirat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.lokirat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lokirat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:0xmrmagnezi.github.io
LokiBot is a stealthy and versatile malware that leverages steganography to conceal its payload within seemingly innocuous images. Once executed, it establishes persistence through scheduled tasks, evades detection by tampering with security software, and exfiltrates sensitive information to a remote command-and-control server.
-
web:any.run
LokiBot, also known as Loki -bot or Loki bot, is an information stealer malware that collects data from the most widely used web browsers, FTP, email clients, and over a hundred software tools installed on the infected machine. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc
-
web:attack.mitre.org
Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads. [1] [2] [3]
-
web:github.com
This repository contains a narrated malware analysis presentation focused on LokiBot, a widely distributed information stealer and remote access trojan. The investigation includes static analysis, behavioral trait identification, and MITRE ATT&CK mapping.
-
web:malpedia.caad.fkie.fraunhofer.de
" Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMe
-
web:success.trendmicro.com
Loki is an info-stealer malware that was first detected on February 2016. This malware first targeted Android systems and its capabilities include stealing credentials, disabling notifications, intercepting communications and data ex filtration.
-
web:www.cisa.gov
LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials.
-
web:www.cisecurity.org
Technical Details LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. The malware steals credentials through the use of a keylogger to monitor browser and desktop activity (Credentials from Password Stores ...
-
web:www.hhs.gov
Technical Details LokiBot, also known as Lokibot, Loki PWS, and Loki -bot, employs trojan malware to steal sensitive informaiton such as usernames, passwords, cryptocurrency wallets, and other credentials. According to one security researcher, in two-thirds of attack attempts, the LokiBot malware arrives in the form of an email attachment.
-
web:www.splunk.com
An analysis on the updated .NET steganography loader delivering Lokibot malware , including evasion techniques, MITRE ATT&CK TTPs, and Splunk detections to enhance threat identification.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.