s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.lokirat

📛 Threat Title

Malware family: Loki RAT

Category: Loki RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.lokirat`. Printable name: Loki RAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.lokirat VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lokirat

IOC database

Type
domain
Value
py.lokirat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.lokirat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/py.lokirat

References (1)

Remediations (10)

  • web:0xmrmagnezi.github.io

    LokiBot is a stealthy and versatile malware that leverages steganography to conceal its payload within seemingly innocuous images. Once executed, it establishes persistence through scheduled tasks, evades detection by tampering with security software, and exfiltrates sensitive information to a remote command-and-control server.

  • web:any.run

    LokiBot, also known as Loki -bot or Loki bot, is an information stealer malware that collects data from the most widely used web browsers, FTP, email clients, and over a hundred software tools installed on the infected machine. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc

  • web:attack.mitre.org

    Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads. [1] [2] [3]

  • web:github.com

    This repository contains a narrated malware analysis presentation focused on LokiBot, a widely distributed information stealer and remote access trojan. The investigation includes static analysis, behavioral trait identification, and MITRE ATT&CK mapping.

  • web:malpedia.caad.fkie.fraunhofer.de

    " Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMe

  • web:success.trendmicro.com

    Loki is an info-stealer malware that was first detected on February 2016. This malware first targeted Android systems and its capabilities include stealing credentials, disabling notifications, intercepting communications and data ex filtration.

  • web:www.cisa.gov

    LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials.

  • web:www.cisecurity.org

    Technical Details LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. The malware steals credentials through the use of a keylogger to monitor browser and desktop activity (Credentials from Password Stores ...

  • web:www.hhs.gov

    Technical Details LokiBot, also known as Lokibot, Loki PWS, and Loki -bot, employs trojan malware to steal sensitive informaiton such as usernames, passwords, cryptocurrency wallets, and other credentials. According to one security researcher, in two-thirds of attack attempts, the LokiBot malware arrives in the form of an email attachment.

  • web:www.splunk.com

    An analysis on the updated .NET steganography loader delivering Lokibot malware , including evasion techniques, MITRE ATT&CK TTPs, and Splunk detections to enhance threat identification.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.