General

  • Target

    15458418d8327e36deaf27b44ef130ff_JaffaCakes118

  • Size

    676KB

  • Sample

    240627-j2hv6sshkq

  • MD5

    15458418d8327e36deaf27b44ef130ff

  • SHA1

    86569ce90fde2f4d7c9df765bc4211c5d8745391

  • SHA256

    0c26809f50f5349e7270d6a183a509a37356ea6109cced6f723236f86ae03a98

  • SHA512

    455df069e9fe73d1ad954f51e20b1b351e61cbbc19420372e30a6782c913fce0e91b80436aaa376b66be87fc67c0701199b922c46662ce617e782a97c139fc71

  • SSDEEP

    12288:2fJzgG7TY76z6hGUOirIET1+6lHwqh6QFeH0sc2lnrZkts12ynvec8c7Ni5sPQmO:UzN6YktxTH5H

Malware Config

Extracted

Family

lokibot

C2

http://142.11.210.173/1/fre.php

http://kbfvzoboss.bid/alien/fre.php

http://alphastand.trade/alien/fre.php

http://alphastand.win/alien/fre.php

http://alphastand.top/alien/fre.php

Targets

    • Target

      15458418d8327e36deaf27b44ef130ff_JaffaCakes118

    • Size

      676KB

    • MD5

      15458418d8327e36deaf27b44ef130ff

    • SHA1

      86569ce90fde2f4d7c9df765bc4211c5d8745391

    • SHA256

      0c26809f50f5349e7270d6a183a509a37356ea6109cced6f723236f86ae03a98

    • SHA512

      455df069e9fe73d1ad954f51e20b1b351e61cbbc19420372e30a6782c913fce0e91b80436aaa376b66be87fc67c0701199b922c46662ce617e782a97c139fc71

    • SSDEEP

      12288:2fJzgG7TY76z6hGUOirIET1+6lHwqh6QFeH0sc2lnrZkts12ynvec8c7Ni5sPQmO:UzN6YktxTH5H

    • Lokibot

      Lokibot is a Password and CryptoCoin Wallet Stealer.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Email Collection

1
T1114

Tasks