General

  • Target

    98e1aa492f377611e489361fbcf1fced75fe6c9028a214aeba35fa7ac577790b

  • Size

    490KB

  • Sample

    240619-pn91dsvdmq

  • MD5

    208c31479a014536a9fe9c13acc0d403

  • SHA1

    e9e082b4a5cbd4ce17168d4164dfa6fab84bf2cd

  • SHA256

    98e1aa492f377611e489361fbcf1fced75fe6c9028a214aeba35fa7ac577790b

  • SHA512

    c1835226ae6bafd4309806773dbfd782dd39f71ffc760a74a822559b017457d9ac1b4f7e53f53bde1bd16150b454d7732855588eba6fc8513ff2a4ac00e98b2a

  • SSDEEP

    12288:+3Omoel/jaCQRwfzt/sWo5hZg1OpckFqUj7DWkR:Hmnl/2Cy/5hi0WkFlN

Malware Config

Extracted

Family

lokibot

C2

http://midwestsoil.top/alpha/five/fre.php

http://kbfvzoboss.bid/alien/fre.php

http://alphastand.trade/alien/fre.php

http://alphastand.win/alien/fre.php

http://alphastand.top/alien/fre.php

Targets

    • Target

      98e1aa492f377611e489361fbcf1fced75fe6c9028a214aeba35fa7ac577790b

    • Size

      490KB

    • MD5

      208c31479a014536a9fe9c13acc0d403

    • SHA1

      e9e082b4a5cbd4ce17168d4164dfa6fab84bf2cd

    • SHA256

      98e1aa492f377611e489361fbcf1fced75fe6c9028a214aeba35fa7ac577790b

    • SHA512

      c1835226ae6bafd4309806773dbfd782dd39f71ffc760a74a822559b017457d9ac1b4f7e53f53bde1bd16150b454d7732855588eba6fc8513ff2a4ac00e98b2a

    • SSDEEP

      12288:+3Omoel/jaCQRwfzt/sWo5hZg1OpckFqUj7DWkR:Hmnl/2Cy/5hi0WkFlN

    • Lokibot

      Lokibot is a Password and CryptoCoin Wallet Stealer.

    • Command and Scripting Interpreter: PowerShell

      Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Email Collection

1
T1114

Tasks