Advertisement
ExecuteMalware

2021-08-05 Lokibot IOCs

Aug 5th, 2021
14,839
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.37 KB | None | 0 0
  1. THREAT IDENTIFICATION: LOKIBOT
  2.  
  3. SUBJECTS OBSERVED
  4. Purchase Order NO_4082021
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Purchase Order NO_4082021.xlsx
  10. 7c93eb8e06a1734cd40e729172eae349
  11.  
  12. LOKIBOT PAYLOAD URLS
  13. http://revolver-reloaded.de/contentcj/vutomecj.exe
  14.  
  15. LOKIBOT PAYLOAD FILE HASHES
  16. 97071E.exe
  17. 7598c86263182dca909e4b70a6e5f2bb
  18.  
  19. LOKIBOT C2
  20. http://arkt.xyz/mrtker4/w2/fre.php
  21.  
  22. C2 PACKET CONTENTS
  23. POST /mrtker4/w2/fre.php HTTP/1.0
  24. User-Agent: Mozilla/4.08 (Charon; Inferno)
  25. Host: arkt.xyz
  26. Accept: */*
  27. Content-Type: application/octet-stream
  28. Content-Encoding: binary
  29. Content-Key: A1795E60
  30. Content-Length: 176
  31. Connection: close
  32.  
  33. HTTP/1.1 404 Not Found
  34. Date: Thu, 05 Aug 2021 13:52:35 GMT
  35. Content-Type: text/html; charset=UTF-8
  36. Connection: close
  37. status: 404 Not Found
  38. CF-Cache-Status: DYNAMIC
  39. Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=%2BSaFzWv8HeVhuZWpAhC6PlLzkid1Efgk3Y348HcFZtYKQAKnLrKPoaKsJhWjc8xJRH6WMIW%2B7Wa3fXDMvbrFdNDQ%2FZOuyGD3i0uOlULiQemtoct5n1zkzCg5mw%3D%3D"}],"group":"cf-nel","max_age":604800}
  40. NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
  41. Server: cloudflare
  42. CF-RAY: 67a081bd89dd4bbf-YUL
  43. alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
  44.  
  45. SUPPORTING EVIDENCE
  46. https://app.any.run/tasks/0f19c470-3fdb-41e9-81d7-733dbabaab02/
  47.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement