ExecuteMalware

2021-08-09 Lokibot IOCs

Aug 9th, 2021
15,091
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.35 KB | None | 0 0
  1. THREAT IDENTIFICATION: LOKIBOT
  2.  
  3. SUBJECTS OBSERVED
  4. purchase order 090821
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. purchase order 090821.xlsx
  10. 97f66886c8ed99dff7103f9057076693
  11.  
  12. LOKIBOT PAYLOAD URLS
  13. http://klipotrim.com/cjnewa/cjuyro.exe
  14.  
  15. LOKIBOT PAYLOAD FILE HASHES
  16. 97071E.exe
  17. 09a33d0fb401a5ab4a5250a799a6689f
  18.  
  19. UNKNOWN FILE HASH
  20. 97071E.hdb
  21. fb527ebc3cd84eb70acb6d6d1ddcc819
  22.  
  23. LOKIBOT C2
  24. http://arkt.xyz/mrtker4/w2/fre.php
  25.  
  26. C2 PACKET CONTENTS
  27. POST /mrtker4/w2/fre.php HTTP/1.0
  28. User-Agent: Mozilla/4.08 (Charon; Inferno)
  29. Host: arkt.xyz
  30. Accept: */*
  31. Content-Type: application/octet-stream
  32. Content-Encoding: binary
  33. Content-Key: A1795E60
  34. Content-Length: 3443
  35. Connection: close
  36.  
  37. HTTP/1.1 404 Not Found
  38. Date: Mon, 09 Aug 2021 16:30:42 GMT
  39. Content-Type: text/html; charset=UTF-8
  40. Connection: close
  41. Status: 404 Not Found
  42. CF-Cache-Status: DYNAMIC
  43. Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=H17TLh4lp8XYZKhy8z2n4Pt9JIY1xoklPWc0GGO21wgL07%2FkumjZh899YK5p%2B67jj5U56uX21OyW8OqqXycebjjvSTcYVbr6SDt6CVtq31HSkxbn0pVZ1CeJBw%3D%3D"}],"group":"cf-nel","max_age":604800}
  44. NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
  45. Server: cloudflare
  46. CF-RAY: 67c25ed7dadfe6bc-EWR
  47. alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
  48.  
  49. File not found.
Advertisement
Add Comment
Please, Sign In to add comment