ExecuteMalware

2021-08-12 Lokibot IOCs

Aug 12th, 2021 (edited)
14,410
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.04 KB | None | 0 0
  1. THREAT IDENTIFICATION: LOKIBOT
  2.  
  3. SUBJECTS OBSERVED
  4. Richiesta di quotazione
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Richiesta di quotazione.gz
  10. 6ea1f325962183bb76eb910bba5d8083
  11.  
  12. LOKIBOT PAYLOAD FILE HASHES
  13. ConsoleApp2.exe
  14. 329693bf1fce73c334b98dedce191db1
  15.  
  16. Renamed and copied to Appdta\Roaming\17E4D9
  17. 97071E.exe
  18. 329693bf1fce73c334b98dedce191db1
  19.  
  20. LOKIBOT C2
  21. http://avatar.ps/modules/five/fre.php
  22.  
  23. C2 PACKET CONTENTS
  24. LOKIBOT C2 PACKET
  25. POST /modules/five/fre.php HTTP/1.0
  26. User-Agent: Mozilla/4.08 (Charon; Inferno)
  27. Host: avatar.ps
  28. Accept: */*
  29. Content-Type: application/octet-stream
  30. Content-Encoding: binary
  31. Content-Key: DA6FF4FE
  32. Content-Length: 149
  33. Connection: close
  34.  
  35. HTTP/1.1 200 OK
  36. Date: Thu, 12 Aug 2021 20:54:09 GMT
  37. Server: Apache
  38. Upgrade: h2,h2c
  39. Connection: Upgrade, close
  40. Content-Length: 23
  41. Content-Type: text/html; charset=UTF-8
  42.  
  43. ........File not found.
  44.  
  45. SUPPORTING EVIDENCE
  46. https://www.virustotal.com/gui/file/9b83e59783b63981f9f85b2939e038531deb96457d91d5d8debc93f396a15272/detection
  47.  
  48.  
Advertisement
Add Comment
Please, Sign In to add comment